Google describes PageBreak as an internal AI agent used by its Product Security team to test first-party web applications. The project began as a pilot in November 2025 and became a fuller project in January 2026. Google says most of its usage is based on Gemini models, while the system is flexible enough to work with different models.
The problem PageBreak targets is not only discovering possible vulnerabilities. It is separating exploitable defects from noisy, unverified output. Google says PageBreak has uncovered more than 500 XSS vulnerabilities across first-party applications, while its validation loop is intended to keep unverified candidates away from product teams.
The result is better described as an agent-plus-verifier system than as a model that independently proves every security claim. The model helps navigate code and application behavior; specialized tooling supplies the evidence.
More info here: https://cybersecuritynews.com/googles-ai-hacker/
Jacob Krell, Sr. Director: Security AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)
“AI is a good fit for vulnerability discovery because it can take an action and check what happened. That gives it something concrete to work with. Google says its PageBreak agent has found more than 500 cross-site scripting (XSS) bugs, which can let an attacker run their own JavaScript in someone else’s browser. When PageBreak spots a possible flaw, a separate validator tries the attack against a running application. If the code runs, there is evidence. If it does not, the finding stays a possibility.
“That is a better use of AI than asking a model to read code and write a confident explanation of why something might be vulnerable. The same approach can work for other issues. The system can try a SQL injection, check whether a file can be retrieved through path traversal, or see whether a server-side request forgery (SSRF) causes the application to contact an internal service. It can run the test, inspect the result, and decide what to try next.
“Google says this has produced a near-zero false-positive rate. That claim applies to the checks PageBreak knows how to run. It does not mean the applications are secure. The agent can still miss a vulnerability if the validator does not cover that type of attack, or if the test environment does not match the real one. That is the false-negative problem.
“I would much rather review a smaller list of vulnerabilities with working evidence than a huge list of theories generated by an AI model. The more security work can be turned into ‘run something, observe the result, and make the next decision,’ the more useful AI becomes. PageBreak is interesting because it applies that idea to real vulnerability testing instead of treating the model’s explanation as proof.”
Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security (https://www.linkedin.com/in/darinfredde)
“What stands out about Google’s PageBreak work is the shift from identifying a potential vulnerability to proving exploitability. That distinction matters. Security teams don’t need more theoretical findings; they need evidence showing what an attacker can really do. We’re seeing offensive security mature from periodic, point-in-time testing toward continuous, evidence-backed validation. Agentic AI can help scale that work by reasoning through attack paths, validating findings, and repeating tests as environments change. The model itself is only part of that equation; the surrounding testing framework, guardrails, evidence, and ability to operate within an organization’s security boundary matter just as much.
“The larger takeaway from PageBreak is that offensive testing is becoming more continuous, autonomous, and evidence-driven. Finding something is no longer enough. We increasingly need to prove it, fix it, and verify that the fix worked.”
Once again I am telling the world that they need to defend against AI related threats. Otherwise your adversaries will will use AI to pwn you in epic fashion.
Related
This entry was posted on October 5, 2026 at 6:37 pm and is filed under Commentary with tags Google. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Google PageBreak AI Finds 500+ Vulnerabilities
Google describes PageBreak as an internal AI agent used by its Product Security team to test first-party web applications. The project began as a pilot in November 2025 and became a fuller project in January 2026. Google says most of its usage is based on Gemini models, while the system is flexible enough to work with different models.
The problem PageBreak targets is not only discovering possible vulnerabilities. It is separating exploitable defects from noisy, unverified output. Google says PageBreak has uncovered more than 500 XSS vulnerabilities across first-party applications, while its validation loop is intended to keep unverified candidates away from product teams.
The result is better described as an agent-plus-verifier system than as a model that independently proves every security claim. The model helps navigate code and application behavior; specialized tooling supplies the evidence.
More info here: https://cybersecuritynews.com/googles-ai-hacker/
Jacob Krell, Sr. Director: Security AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)
“AI is a good fit for vulnerability discovery because it can take an action and check what happened. That gives it something concrete to work with. Google says its PageBreak agent has found more than 500 cross-site scripting (XSS) bugs, which can let an attacker run their own JavaScript in someone else’s browser. When PageBreak spots a possible flaw, a separate validator tries the attack against a running application. If the code runs, there is evidence. If it does not, the finding stays a possibility.
“That is a better use of AI than asking a model to read code and write a confident explanation of why something might be vulnerable. The same approach can work for other issues. The system can try a SQL injection, check whether a file can be retrieved through path traversal, or see whether a server-side request forgery (SSRF) causes the application to contact an internal service. It can run the test, inspect the result, and decide what to try next.
“Google says this has produced a near-zero false-positive rate. That claim applies to the checks PageBreak knows how to run. It does not mean the applications are secure. The agent can still miss a vulnerability if the validator does not cover that type of attack, or if the test environment does not match the real one. That is the false-negative problem.
“I would much rather review a smaller list of vulnerabilities with working evidence than a huge list of theories generated by an AI model. The more security work can be turned into ‘run something, observe the result, and make the next decision,’ the more useful AI becomes. PageBreak is interesting because it applies that idea to real vulnerability testing instead of treating the model’s explanation as proof.”
Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security (https://www.linkedin.com/in/darinfredde)
“What stands out about Google’s PageBreak work is the shift from identifying a potential vulnerability to proving exploitability. That distinction matters. Security teams don’t need more theoretical findings; they need evidence showing what an attacker can really do. We’re seeing offensive security mature from periodic, point-in-time testing toward continuous, evidence-backed validation. Agentic AI can help scale that work by reasoning through attack paths, validating findings, and repeating tests as environments change. The model itself is only part of that equation; the surrounding testing framework, guardrails, evidence, and ability to operate within an organization’s security boundary matter just as much.
“The larger takeaway from PageBreak is that offensive testing is becoming more continuous, autonomous, and evidence-driven. Finding something is no longer enough. We increasingly need to prove it, fix it, and verify that the fix worked.”
Once again I am telling the world that they need to defend against AI related threats. Otherwise your adversaries will will use AI to pwn you in epic fashion.
Share this:
Like this:
Related
This entry was posted on October 5, 2026 at 6:37 pm and is filed under Commentary with tags Google. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.