DARPA Selects Xint to Use AI in Securing Military Messaging Apps
DARPA selects Xint to use AI for securing military messaging app code and binaries.
Summary
DARPA has chosen Xint to research and develop AI-driven application security for analyzing military messaging apps. Xint's technology, which won the AIxCC competition, will examine source code and compiled binaries to identify and patch vulnerabilities, aiming to secure Department of War communications and enhance software supply chain risk assessment.
Full text
The Defense Advanced Research Projects Agency (DARPA) selected Xint to research the use of autonomous AI application security for deep analyses of internally and externally developed messaging applications that are used throughout the Department of War. DARPA was established in 1958 following the USSR’s launch of Sputnik in 1957. The purpose was to ensure the US would never again be surprised by the technological achievements of foreign countries. DARPA consequently partners with and supports private industry in the development of cutting edge new technology to keep the US ahead of rivals. This is a big deal for Xint. Previous DARPA engagements with private industry have led to the development of the internet (via ARPANET), GPS and Siri. Xint (which emerged within Theori) was selected following its performance (it was one of the three winners) in DARPA’s Artificial Intelligence Cyber Challenge (AIxCC), a two-year, $29.5 million competition. It is now tasked with analyzing source code, whether internally developed by messaging apps such as Signal or open source projects. It will also analyze compiled binaries using a new service launched in September 2026. The service is designed to assess software supply chain risk across compiled code running in environments such as agents, on-premises software, appliances, network daemons, and other services. “Messaging and communications applications are unique in that an attacker needs read-only access to compromise the entire point of the app,” said Andrew Wesie, CTO and co-founder at Xint. “Third-party SDKs and libraries embedded in these apps can create hidden data risks, where even seemingly minor leaks may expose a user’s location or other personally identifiable information during sensitive communications – often without the user or even the developer knowing.” He explained Xint’s operation to SecurityWeek. DARPA is seeking to ensure that Department of War messaging is secure against external, and especially foreign, eavesdropping. Xint technology, using the latest frontier LLM models (he describes Xint as “really just a harness and a workflow around frontier elements”) is able to examine all the source code involved in the apps concerned, reverse engineering binaries as necessary. So, for messaging from Android, Xint would look at the app itself, the Linux kernel, and any other components of the Android ecosystem that sit between the app and the kernel. Advertisement. Scroll to continue reading. Having access to every aspect of the system being analyzed, it can then detect and investigate any vulnerability across the entirety of the attack surface, automatically triage the vulnerabilities based on accessibility to an attacker, and then generate patches for any vulnerability that could be useful to attackers. From this, DARPA gets the ability to secure War Department communications, while Xint retains a technology that can be applied to any system or application for any commercial customer, partly but not completely, funded by DARPA – and the US receives a technology that maintains its position at the cutting edge of innovation. “Right now,” continued Wesie, “we’re talking to customers that have written their own code, such as a web app. We want to help them secure that code.” This security is offered as a SaaS solution. The developer is invited to run the code through Xint before its release to be vulnerability-free and then run additional regular scans to detect any new vulnerabilities introduced after the initial release. Xint is continuing to evolve its service. “There are some enterprises that are interested in running everything within their own data center because they don’t want any of their source code leaving that data center,” said Wesie.” That’s still a work in progress, mainly because we won’t be able to use the latest OpenAI models, the latest Anthropic models – we cannot automatically use the latest LLM models and keep everything within a customer’s data center.” Xint is already in use with customers. “Our relationship with and funding from DARPA is allowing us to continue developing additional capabilities. There is always more we can do.” Meanwhile, the DARPA / Xint relationship is a major confirmation of the synergy of cooperation. DARPA gets secure messaging for the Department of War, Xint gets a major commercial opportunity, and the market gets an opportunity for increased security. Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability Related: Roundcube Webmail Vulnerability in Attackers’ Crosshairs Related: Critical WordPress Vulnerability Exploited Immediately After Disclosure Related: Critical F5 BIG-IP Vulnerability Exploited as Zero-Day Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend Modulate Raises $25 Million to Advance Deepfake DetectionIonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderOuterlimit Raises $16 Million to Stop Rogue AI Agents From Causing HarmCISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastRansomware Attacks on Manufacturers Surge as Supply Chain Risk GrowsFirst Agentic AI Data Breach Reported to Spanish RegulatorEU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws Latest News New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data LeaksRemoteThreat Launches With $7 Million for Offensive Operations PlatformReco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksPentagon Personnel Agency Data Breach Impacts 3 Million PeopleRig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity RisksFour Cyber Threats Harboring Big Plans for the FutureOpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveDoppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working to