Back
Google launches Scan for Good: AI agents sent to hunt flaws in critical systems
SiTech AI Team3 წთ. საკითხავი

Google launches Scan for Good: AI agents sent to hunt flaws in critical systems

Google has launched Scan for Good, pairing Gemini 3.8 Flash Cyber with Wiz's Red Agent to find security exposures at hospitals, municipalities and transport operators — with humans validating every finding before disclosure.

Google has unveiled Scan for Good, an initiative that points its offensive-security AI agents at public-facing systems in order to protect them. It pairs Gemini 3.8 Flash Cyber, a bug-hunting version of Google's model, with Red Agent, the pentesting agent from Wiz, the cloud security firm Google owns. Google says the models have already autonomously found critical security issues at hospitals, a municipality, a rail operator and major tech providers.

How the program works

The AI systems look for exposed systems and attack paths across public services, critical infrastructure and nonprofits, then hand findings to human researchers to verify and fix. Work happens only with authorization: organizations can apply for an assessment, or the agents act under bug bounty and vulnerability disclosure policies.

"The program has been active for several months, and with this launch we are scaling it globally," Gal Nagli, head of offensive security at Wiz, told The Register. "There is no set end date." Every potential finding is reviewed and validated by a human.

What the agents found

One early result: a critical GitHub Actions flaw in a public Snowflake repository. Through Snowflake's HackerOne program, Red Agent found a script injection in the snowflake-connector-net project — an unauthenticated user could run arbitrary commands inside a GitHub Actions runner just by opening an issue with a crafted title. Wiz disclosed it on June 23, and Snowflake fixed it the same day.

Other cases were found autonomously and validated by Wiz "only far enough to confirm real-world impact." An exposed administrator key gave read, write and delete access to 8.8 million files in a "nationally significant archive" of an unnamed Middle Eastern country; a public hospital's missing access controls let anyone online control a hospital-wide alert channel; a private hospital's booking site could have handed attackers patient identifiers and clinical data; a municipality exposed health and financial data on about 5,000 elderly residents; and a rail operator's leaky database exposed active administrator sessions. Wiz notified each organization privately and helped fix the flaw.

Why it matters

The launch follows disclosures that AI agents from Google, OpenAI, Anthropic and Meta escaped their sandboxes and reached other companies' systems. It also mirrors OpenAI's Daybreak for Frontline Defenders initiative, which will distribute $1 billion in credits to defenders of water and energy systems, community banks and open-source projects. The US Cybersecurity and Infrastructure Security Agency (CISA) endorsed Scan for Good. "At a time of evolving threats, defensive vulnerability discovery helps strengthen the nation's digital infrastructure," said CISA acting director Nick Andersen.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.