
What's in the SOSS? An OpenSSF Podcast AIxCC Part 4 – Cyber Reasoning Systems: The Real-World Journey After AIxCC
9 snips
Feb 10, 2026 Jeff Diecks, OpenSSF technical lead on the AI Cyber Challenge with 20+ years in open source, discusses how AI-powered vulnerability detectors moved from competition to real-world use. He covers real bug findings in the Linux kernel and CUPS. He explains the OSS-CRS standard infrastructure for mixing system components and shares lessons on responsibly reporting AI-generated security findings to maintainers.
AI Snips
Chapters
Transcript
Episode notes
Competition Drove Open Research And Real Impact
- The AIxCC aimed to create systems that both find and fix vulnerabilities in critical open source software.
- Competitors were required to open-source their work, accelerating real-world adoption and collaboration.
Different Teams, Different Strengths
- Team Theory used pure LLMs rather than fuzzing, showing different viable technical approaches.
- Another team generated excellent patches but lost competition credit due to a late architectural change.
Polling LLMs For Verdicts
- One team submitted potential findings to multiple LLMs for verdicts, effectively polling models for consensus.
- The hosts joked it was like getting "eight out of nine dentists" to agree before submission.

