// AI threat desk · 1 Oct 2026
Home/SUPPLY · AI Supply Chain
AI Supply ChainMediumAGENT

DARPA Picks Xint to Use AI on Military Messaging App Flaws

The US Defense Advanced Research Projects Agency (DARPA) announced on Sep 29, 2026 that it has selected Xint, a winning team from AIxCC, to use autonomous AI technology to analyze source code and binaries of Department of Defense communication apps for exploitable vulnerabilities. The technology will also be offered to commercial customers.

Illustrative image: military communication security concept, image source: owleval.com
File photo: Illustrative image: military communication security concept, image source: owleval.com. Photo: rawpixel (CC0)
Key takeaways
  • DARPA has selected Xint, a startup originating from Theori, to use autonomous AI technology to analyze source code and compiled binaries of Department of Defense communication apps (including Signal) to find security vulnerabilities.
  • Xint is one of three winners of DARPA’s two year, $29.5 million ‘AI Cyber Challenge’ (AIxCC). Its technology can automatically classify vulnerability risk and generate patches.
  • Xint’s technology is also offered as a SaaS product to commercial customers for pre release and post release code security scanning, but it cannot yet fully run the latest frontier models within customers’ own data centers.
On this page

DARPA selects Xint to analyze Department of Defense communication software

According to a SecurityWeek report, the US Defense Advanced Research Projects Agency (DARPA) selected Xint on Sep 29, 2026 to research the use of autonomous AI application security technology to deeply analyze communication apps developed both internally and externally for the Department of Defense.

DARPA was established in 1958, following the Soviet Union’s launch of an artificial satellite. It has long partnered with private companies to develop frontier technologies. Past collaborations have produced the internet (ARPANET), GPS and Siri.

Technology covers source code and compiled binary analysis

According to the report, Xint originated from the startup Theori and was earlier selected as one of three winners in DARPA’s two year, roughly $29.5 million ‘AI Cyber Challenge’ (AIxCC).

DARPA has commissioned Xint to analyze source code, whether from internally developed projects or open source projects involved in communication apps such as Signal. Xint also uses a new service launched in Sep 2026 to analyze compiled binaries, assessing software supply chain risk in environments such as military agents, on premise software, devices and network daemons.

Co-founder says reading a messaging app can compromise the entire system

Andrew Wesie, chief technology officer and co-founder of Xint, told SecurityWeek that communication and messaging apps are unique in that an attacker only needs read access to compromise the entire application. Third party SDKs and libraries can create hidden data risks. Even minor data leaks can expose a user’s location or other personally identifiable information within sensitive communications, and neither users nor even developers themselves may be aware of it.

Wesie said Xint’s technology is essentially ‘a set of tools and workflows built around frontier models’. It uses the latest frontier large language models to comprehensively examine all source code involved in an application and, when necessary, reverse engineer binaries. For example, when analyzing an Android app, it examines the app itself, the Linux kernel, and other ecosystem components between the app and the kernel.

Technology also extended to commercial customers, but on premise deployment still pending

The report states that Xint’s technology can automatically classify vulnerabilities based on attacker accessibility and generate patches for vulnerabilities that could be exploited by attackers. The technology is also offered as a SaaS product to commercial customers for regular vulnerability scanning before and after software release.

Wesie said some enterprise customers want to run the entire system within their own data centers to prevent source code leakage, but this capability is still under development. The main reason is that the latest OpenAI and Anthropic models cannot yet be automatically used within customers’ data centers.

What to do now

  1. Assess third party SDKs and libraries used in your own communication or collaboration apps to check for hidden data leakage risks.
  2. Before procuring military grade or AIxCC related AI security audit services, confirm whether the service supports on premise data center deployment and which model versions are used.
  3. Establish continuous pre release and post release vulnerability scanning for released software, and prioritize patching vulnerabilities that could be exploited by attackers.

FAQ

What is Xint and what is its relationship with DARPA?

Xint is a team that originated from the startup Theori. It was earlier selected as one of three winners in DARPA’s two year, roughly $29.5 million ‘AI Cyber Challenge’ (AIxCC). It has now been commissioned by DARPA to research using AI to analyze vulnerabilities in Department of Defense communication apps.

What scope does Xint’s AI technology analyze?

According to the report, Xint analyzes source code of internally and openly developed communication apps (such as Signal), and uses a new service launched in Sep 2026 to analyze compiled binaries, covering environments such as agents, on premise software, devices and network daemons.

Is this technology already available to general commercial customers?

Yes. According to Xint chief technology officer Andrew Wesie, the technology is already offered as a SaaS product to commercial customers for vulnerability scanning before and after software release. However, it does not yet fully support customers running the latest frontier AI models within their own data centers.

Does this DARPA and Xint collaboration involve any known CVE vulnerabilities?

The report does not mention any specific CVE numbers. This collaboration is research in nature, aimed at using AI to proactively discover and patch potential vulnerabilities in Department of Defense communication apps, rather than responding to a specific publicly disclosed vulnerability.

Sources

  1. SecurityWeek: DARPA Selects Xint to Use AI in Securing Military Messaging AppsPrimary
Explore with AI