This page was machine-translated and may differ from the original. View original
Theori Xint Selected as DARPA 'AI Communication App Security' Research Contractor
3 Signal Android Vulnerabilities Detected Within 1 Hour, U.S. Department of Defense Messenger App Supply Chain Risk Assessment Underway
Xint, the AI autonomous penetration testing platform developed by Theori, an offensive cybersecurity company, will be deployed in a U.S. Defense Advanced Research Projects Agency (DARPA) research project. The focus is on analyzing vulnerabilities in communication apps used by the U.S. Department of Defense with AI and assessing software supply chain risks.
Theori announced on the 30th that it has been selected as a contractor for DARPA's "Autonomous AI Application Security" research project.
Xint will be utilized for in-depth analysis of self-developed and open-source messenger apps used across the U.S. Department of Defense, and will also evaluate software supply chain risks in various environments through binary analysis.
Signal Vulnerabilities Detected and Patched
During the proposal process, Xint analyzed the Android version of encrypted messenger app Signal and detected 3 improper exception handling (uncaught-exception) vulnerabilities causing app force-closure within 1 hour.
The vulnerabilities were reported to the Signal development team and resolved through version 8.11 update.
Park Se-jun, CEO of Theori, stated, "While encryption areas in messaging apps undergo rigorous verification, code interfacing with networks or operating systems often does not receive the same level of scrutiny and becomes an easy target for attackers. Regardless of source code availability, we will support regular and precise verification of such code using binary analysis alone."
Xint Composition and Theori's DARPA Collaboration History
Xint consists of three modules: △Xint Code (AI-based white-box penetration testing) △Xint Web (AI-based black-box penetration testing) △Xint Pulse (on-demand penetration testing solution).
Theori ranked among the top in DARPA's 2025 "AI Cyber Challenge (AIxCC)."
AIxCC is a competition testing AI-based vulnerability detection and patch capabilities, with a total prize pool of $29.5 million (approximately 40 billion won) conducted over 2 years.
Subsequently, Theori has been participating in DARPA's bug bounty program, proactively analyzing vulnerabilities in major open-source software.
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.














