Hack.lu 2026

Project Rudzik - LLM assisted vulnerability hunting in open source projects

Securing core open source projects is important for obvious reasons.
AI / LLMs are another potential option in our toolset to help with this.
In this research I tested different prompts, approaches and versions of LLMs to aid in my code reviewing process. This research led to a significant list of vulnerability findings.


In this talk, I go over some lessons learned from my LLM assisted security research.
Topics covered:

  • Different approaches tested
  • Some lessons learned
  • A few vulnerabilities discovered
Jeroen Pinoy

I am a computer scientist with a background in software testing (automation), incident handling, threat intelligence sharing and security research.