Session

AI Found a 0-Day in Metal3. What Happens Next?

AI-powered vulnerability discovery is here, and in 2026 it is no longer just a noise generator. These pipelines can uncover real 0-days, but a plausible finding is only the start. Maintainers must still verify the claims and determine their actual impact.

As Metal3's Security Lead, I am the primary analyzer and coordinator for incoming vulnerability reports. I've also built an AI vulnerability discovery pipeline, giving me insight into both sides of the process. Bare-metal provisioning is a useful case study: modern cloud-native architecture meets legacy drivers, deprecated protocols and external integrations. Vulnerabilities are rarely proven by a simple automated crash.

We examine what these pipelines can produce, where their reports fall short and what maintainers look for during triage. Users will see the work behind a security response, while researchers and contributors will learn what turns pipeline output into an actionable report.

Tuomo Tanskanen

Principal Security Developer at Ericsson

Helsinki, Finland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top