DARPA chooses Xint.io to research source code vulnerabilities

On September 29, Xint announced that the U.S. government’s Defense Advanced Research Projects Agency (DARPA) has selected Xint to research the use of autonomous AI application security to conduct deep security analyses of internally and externally developed messaging applications that are used throughout the Department of War.

As part of its submission, Xint identified in a single, one-hour scan, three uncaught-exception vulnerabilities that caused the Android version of the encrypted messaging application Signal to crash. These bugs were responsibly disclosed to Signal project maintainers and patched in the 8.11 release.

“If you’re the target of state-sponsored hackers, whether you’re the military, a major financial institution, a critical infrastructure provider, or a technology enterprise, you have the highest requirements for application security, especially for keeping communications private,” said Brian Pak, CEO and co-founder of Theori and Xint. “The encryption in a messaging app is the part that gets reviewed. The code around it, everything touching the network, and the operating system, rarely gets the same scrutiny and that’s where an attacker goes. We can now check that code cost-effectively enough to do it routinely, with the source code or with only a binary.”

“Messaging and communications applications are unique in that an attacker needs read-only access to compromise the entire point of the app,” said Andrew Wesie, CTO and co-founder at Xint. “Third-party SDKs and libraries embedded in these apps can create hidden data risks, where even seemingly minor leaks may expose a user’s location or other personally identifiable information during sensitive communications – often without the user or even the developer knowing. That is why independent attestation is critical.”

Xint and its parent company Theori have over a decade of experience working with commercial and governmental organizations to secure their code and applications. That work most recently culminated with the launch of Project Canopy, a public interest initiative disseminating AI-powered preemptive defense capabilities to organizations ranging from major companies across Asia and Europe to civilian infrastructure and open-source software (which often lacks security budgets).

DARPA and Xint first started working together in 2025 when Xint competed in DARPA’s Artificial Intelligence Cyber Challenge (AIxCC), a two-year, $29.5 million competition bringing together some of the top security researchers in the world. As one of the top performers, Xint continued working with DARPA as part of a bounty program to uncover and remediate vulnerabilities in critical open source software projects.

Source: Xint

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.