AI is changing vulnerability research faster than most security programs are adapting. The code that runs modern applications is increasingly public, reusable, and machine-readable, while powerful models can now inspect repositories, trace sensitive code paths, and surface exploitable behavior before a CVE, advisory, or patch exists.
Raven will reveal original research mapping the
14 most powerful software families behind command execution, authentication, network access, deserialization, native code, and other high-impact capabilities.
We’ll show why these components become invisible once the application starts, how recent cases like Log4j2 illustrate the gap between vulnerability discovery and traditional defenses, and why runtime attribution is becoming essential to understand - and prevent - what individual libraries are actually doing inside production.