Policy Pulse - Issue #30 | Week of August 23, 2026 Mandiant found more than 100 critical flaws in two days with an agentic review harness. NIST opened two new comment windows, and CISA added nine actively exploited vulnerabilities. Policy Pulse - Issue #30 | Week of August 23, 2026 Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. Top Story Mandiant just made AI-scale vulnerability disclosure measurable On August 18, Mandiant published the architecture and early results of its Agentic Vulnerability Discovery Harness. In one incident-response engagement, the system found more than 100 true-positive critical vulnerabilities in two days. Across ten months of use, Mandiant says the harness has processed tens of millions of lines of code, run thousands of analysis pipelines, generated tens of thousands of findings, produced 12 assigned CVEs, and left another dozen findings in active disclosure. (Mandiant) The useful bit is not just the volume. Mandiant built explicit gates around it: agents create a threat model, discover entry points, trace control and data flow, generate hypotheses, and attack those hypotheses with multiple validators. Human consultants then reproduce exploitation, write proof-of-concept code, discard false positives, deduplicate the survivors, and prepare formal disclosures. That is closer to a disclosure production line than a faster scanner. Why it matters for VDP: AI-scale intake is no longer a hypothetical future problem. A single team has demonstrated more than 100 critical findings in 48 hours while keeping a human validation gate. Program operators now need a comparable receiving system: machine-readable evidence requirements, aggressive duplicate clustering, support for chained findings, clear CNA routing, and enough coordination capacity to keep validated reports from becoming a new backlog. Upcoming Deadlines & Events | Date | Agency | Event/Deadline | Action Required | Link | |---|---|---|---|---| | Aug 24, 2026 |