SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
TrendAI tops CyberGym with 97% exploit-remediation rate

TrendAI tops CyberGym with 97% exploit-remediation rate

Fri, 28th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

TrendAI said its agentic exploit-remediation engine, AESIR, ranked first on the CyberGym benchmark with a 97% success rate.

CyberGym is an independent benchmark developed at the University of California, Berkeley, to test AI-driven security tools against confirmed software vulnerabilities. In TrendAI's account of the results, AESIR scored almost four percentage points above the previous leader's 93.2% mark.

The benchmark evaluates how well tools identify and remediate vulnerabilities in a controlled environment. It uses 1,507 confirmed vulnerabilities drawn from 188 large open-source software projects widely used by enterprises.

For TrendAI, the ranking is a public test of a product designed to shorten the time between the discovery of a weakness and the point at which defenders can reduce the risk. It describes that period as the exposure window and argues that AI is shrinking the time before attackers can exploit flaws.

According to TrendAI, AESIR begins by identifying weak spots that static methods might miss. It then validates each finding, produces a proof of concept, and moves to detection and virtual patching rather than waiting for a standard software patching cycle.

TrendAI linked that approach to a broader shift in cyber defence, as organisations look for tools that can prioritise exploitable flaws instead of treating all vulnerability findings equally. Security teams have long struggled with large backlogs of alerts, many of which are difficult to verify or address quickly.

Benchmark test

CyberGym focuses on real-world remediation rather than broad claims about AI performance. By concentrating on confirmed vulnerabilities in major open-source projects, it aims to measure whether an automated system can move from identification to practical action in environments that resemble enterprise software estates.

That matters because open-source components sit deep within business applications, cloud services, and internal systems. When a flaw appears in a widely used project, companies often race to determine whether they are exposed and what temporary controls they can put in place before an official patch is applied.

TrendAI said AESIR is supported by more than 20 years of vulnerability research and exploit intelligence, including the TrendAI Zero-Day Initiative. It described the programme as a vendor-agnostic source of vulnerability intelligence that informs how the system assesses and validates software weaknesses.

Rachel Jin, Chief Platform and Business Officer and Head of TrendAI, addressed the significance of the result in a statement about how companies use AI in security.

"CyberGym's validation changes what's possible for enterprises adopting AI. The race isn't to find first. It's to close the exposure window. Cybersecurity has been defined by the scramble from discovery to exploitation; our job is to make that gap meaningless by compressing exposure time towards zero. Our advantage is turning validated vulnerability intelligence into effective risk reduction faster," Jin said.

TrendAI also said the same engine is used to identify threat actors already exploiting vulnerabilities in live environments. That suggests it is positioning AESIR not only as a remediation tool, but also as part of a broader threat-intelligence workflow for security operations teams.

Australian focus

TrendAI framed the benchmark result in the context of Australian enterprise adoption of AI systems. As businesses introduce more AI tools into internal operations and customer-facing services, defenders face a broader attack surface spanning models, software dependencies, and integration layers that can create new points of weakness.

Mick McCluney, ANZ Field Chief Technology Officer at TrendAI, said the benchmark result was relevant to organisations in the local market.

"Achieving this independent recognition demonstrates TrendAI's capability to support Australian enterprises to securely adopt AI, while closing the exposure window faster than attackers can exploit it. Through our strategic partnerships and platform innovation, we are leveraging seven AI models across providers including Anthropic, Google and OpenAI, increasing our ability to maximise detection and remediation accuracy," McCluney said.

The reference to multiple model providers points to another trend in the security software market: vendors are combining several large language models and specialist systems rather than relying on one model alone. Suppliers argue that this can improve consistency across tasks such as code analysis, exploit validation, and prioritisation, though independent testing remains limited.

Benchmark rankings alone do not determine how a tool will perform in a company's own environment, where security teams must deal with legacy systems, custom software, and operational constraints. Even so, an independently run test based on confirmed vulnerabilities offers a clearer comparative measure than many of the broader claims now common in the market for AI security products.

CyberGym evaluates AI security tooling against 1,507 confirmed vulnerabilities drawn from 188 large open-source software projects used across enterprises.