AmericasCyberTechnology

DARPA Taps Xint to Find Flaws in Pentagon Messaging Apps

The Defense Advanced Research Projects Agency (DARPA) has selected cybersecurity firm Xint to research autonomous artificial intelligence to detect software vulnerabilities in messaging applications across the US Department of Defense.

The initiative directs the company to audit existing solutions that are internally developed, open-source, and proprietary.

Xint’s platform automatically flags and ranks vulnerabilities based on accessibility while generating recommended patches by analyzing source code or compiled binaries only, extending security checks to third-party libraries and underlying system components.

While currently offering a hosted cloud-based scanning service, the firm is working on on-site fielding options for environments with strict data isolation requirements.

Brian Pak, CEO at Xint, said that the project addresses a gap in countering state-sponsored hackers through an optimized approach.

“Whether you’re the military, a major financial institution, a critical infrastructure provider, or a technology enterprise, you have the highest requirements for application security, especially for keeping communications private,” Pak explained.

“The encryption in a messaging app is the part that gets reviewed. The code around it, everything touching the network, and the operating system, rarely gets the same scrutiny and that’s where an attacker goes. We can now check that code cost-effectively enough to do it routinely.”

Offering ‘Independent Attestation’

The contract follows the company’s top performance in DARPA’s two-year, $29.5-million Artificial Intelligence Cyber Challenge.

During preliminary testing, Xint uncovered three previously unknown vulnerabilities in the Android release of the encrypted messaging application Signal within one hour.

The bugs were disclosed and patched in the application’s version 8.11 in May.

“Messaging and communications applications are unique in that an attacker needs read-only access to compromise the entire point of the app,” said Andrew Wesie, chief technology officer and co-founder at Xint.

“Third-party [Software Development Kits] and libraries embedded in these apps can create hidden data risks, where even seemingly minor leaks may expose a user’s location or other personally identifiable information during sensitive communications — often without the user or even the developer knowing. That is why independent attestation is critical.”

Related Articles

Back to top button