cd /news/large-language-models/an-llm-assisted-security-review-of-g… · home topics large-language-models article
[ARTICLE · art-80721] src=isgroup.biz ↗ pub= topic=large-language-models verified=true sentiment=· neutral

An LLM-assisted security review of GlobaLeaks: 41 findings for –$3,140

A security review of GlobaLeaks using LLMs identified 29 vulnerabilities, 12 denial-of-service issues, and 42 hardening recommendations at a total cost of approximately $3,140 in API calls, averaging $77 per confirmed finding before human validation. The review, conducted by an unnamed team, found that the most advanced reasoning model accounted for 62% of the budget while processing only 7% of tokens, indicating that deep analysis remains more expensive but increasingly accessible for organizations developing critical software.

read1 min views1 publishedJul 30, 2026
An LLM-assisted security review of GlobaLeaks: 41 findings for –$3,140
Image: source

We spent approximately $3,140 on API calls to conduct a security review of GlobaLeaks, a software platform that had already undergone six independent professional audits over the past thirteen years.

The review identified 29 vulnerabilities, 12 denial-of-service issues, and 42 hardening recommendations. The average cost was approximately $77 per confirmed finding, before human validation.

The total spend is one of the most relevant figures. Reviewing an entire codebase, line by line and against the main known classes of software weakness, has traditionally required weeks of work, specialised expertise, and substantial budgets. This type of analysis is now far more accessible.

The distribution of costs was also notable. The model with the most advanced reasoning capabilities accounted for 62% of the budget while processing only 7% of the tokens. Standard models handled most of the volume at a significantly lower cost.

Deep analysis remains more expensive than broad coverage, but the difference is no longer large enough to represent a significant barrier.

For organisations developing critical software, the implication is clear: systematically reviewing an entire codebase in depth is now within reach of many more people and organisations. The full report, including the methodology and a breakdown of costs by model, is available here: What Can an Attacker Find With an LLM?

#CyberSecurity #ApplicationSecurity #LLM #SecureCodeReview #ISGroup

── more in #large-language-models 4 stories · sorted by recency
── more on @globaleaks 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/an-llm-assisted-secu…] indexed:0 read:1min 2026-07-30 ·