1.24 billion tokens. 12,000 model requests. 29 confirmed vulnerabilities in software already hardened by a decade of independent audits. A landmark European study on LLM-driven vulnerability research – and a case for European digital sovereignty in security.
Italy, 31st Jul 2026 – As Europe pushes for strategic autonomy in critical technologies, a European cybersecurity firm has just demonstrated what that autonomy looks like in practice. ISGroup, an offensive-security company based in Italy and serving organisations across Europe, has published “What Can an Attacker Find With an LLM?” – one of the most extensive public studies to date on using frontier AI models to identify software vulnerabilities, conducted entirely with European expertise and rigorous, transparent methodology.
The message to European boardrooms and institutions is direct: attackers are already exploring AI-assisted vulnerability discovery. Europe cannot afford to depend exclusively on overseas providers to understand – and defend against – this shift. Sovereignty in cybersecurity means having this capability within Europe, accountable to European organisations and aligned with European regulatory frameworks.
To prove the point, ISGroup chose a demanding target: GlobaLeaks, the open-source whistleblowing platform used by newsrooms, companies, and public administrations across Europe and beyond to protect sources – software refined over more than a decade and already reviewed through multiple independent security audits. Using frontier models, ISGroup processed approximately 1.24 billion tokens across 12,000 model requests, generating 110 candidate findings. Every candidate was manually triaged by ISGroup’s researchers, with reproduction, impact assessment, and final classification remaining firmly in expert human hands.
The result: 29 confirmed vulnerabilities, 12 denial-of-service issues, and 42 hardening observations, all responsibly disclosed and the most critical already fixed – a concrete contribution to the resilience of software that protects whistleblowers, a value enshrined in European law through the EU Whistleblowing Directive.
The study also delivers what European decision-makers need most: transparency on real costs, a documented methodology – threat model, taxonomy of weakness classes, strict evidence requirements – and an honest account of the limitations: false positives, non-deterministic results, and the indispensable role of expert validation.
For European organisations, the implications are immediate. Continuous, repository-wide security review – once the preserve of large budgets and weeks of specialist effort – is now within reach for companies of every size and sector. From regulated industries facing NIS2 and DORA obligations to software vendors preparing for the Cyber Resilience Act, ISGroup’s research-driven approach is designed to serve the full spectrum of European enterprises and institutions.
“Artificial intelligence does not replace specialist expertise, but it increases the amount of code a team can analyse and reduces the cost of doing so,” said Francesco Ongaro, founder of ISGroup. “Experts still have the decisive role of distinguishing a plausible hypothesis from a real vulnerability.”
With this publication, ISGroup positions itself as a reference point for AI-assisted offensive security in Europe – proof that world-class security research does not need to be imported.
The full report, including methodology, costs, and complete results, is available at: https://www.isgroup.biz/en/cyber-security/llm-based-code-security-review-costs-findings-methodology.html
About ISGroup: ISGroup is a European cybersecurity company based in Italy, specialising in offensive security, penetration testing, and security research. ISGroup supports European enterprises, institutions, and software vendors of all sizes in securing critical software and infrastructure, with a research-driven approach rooted in European values of transparency and accountability.
Notes for Editors
Francesco Ongaro is available for interviews and technical briefings. A one-page summary of the methodology and aggregated data on model usage are available upon request.
About ISGroup
ISGroup S.r.l. is an Italian cybersecurity company serving clients around the world across a wide range of industries. The company specialises in security research, security assessments, penetration testing, and advanced security analysis of applications and infrastructure. Website: www.isgroup.biz
Press Contact
Francesco Ongaro
Founder, ISGroup S.r.l.
Email: francesco.ongaro@isgroup.it
Phone: +393518158844 (WhatsApp)
www.isgroup.it ITALY
www.isgroup.biz WORLD
Media Contact
Organization: ISGroup S.r.l.
Contact Person: Francesco Ongaro
Website: https://www.isgroup.biz
Email: Send Email
Country:Italy
Release id:47785
The post European Cybersecurity Firm ISGroup Shows What AI-Powered Attackers Can Find – and Why Europe Must Build This Capability at Home appeared first on King Newswire. This content is provided by a third-party source.. King Newswire makes no warranties or representations in connection with it. King Newswire is a press release distribution agency and does not endorse or verify the claims made in this release. If you have any complaints or copyright concerns related to this article, please contact the company listed in the ‘Media Contact’ section
Disclaimer: The views, suggestions, and opinions expressed here are the sole responsibility of the experts. No Brite Research journalist was involved in the writing and production of this article.