{"slug": "an-llm-assisted-security-review-of-globaleaks-41-findings-for-3140", "title": "An LLM-assisted security review of GlobaLeaks: 41 findings for –$3,140", "summary": "A security review of GlobaLeaks using LLMs identified 29 vulnerabilities, 12 denial-of-service issues, and 42 hardening recommendations at a total cost of approximately $3,140 in API calls, averaging $77 per confirmed finding before human validation. The review, conducted by an unnamed team, found that the most advanced reasoning model accounted for 62% of the budget while processing only 7% of tokens, indicating that deep analysis remains more expensive but increasingly accessible for organizations developing critical software.", "body_md": "We spent approximately $3,140 on API calls to conduct a security review of [GlobaLeaks](https://www.globaleaks.org/), a software platform that had already undergone six independent professional audits over the past thirteen years.\n\nThe review identified 29 vulnerabilities, 12 denial-of-service issues, and 42 hardening recommendations. The average cost was approximately $77 per confirmed finding, before human validation.\n\nThe total spend is one of the most relevant figures. Reviewing an entire codebase, line by line and against the main known classes of software weakness, has traditionally required weeks of work, specialised expertise, and substantial budgets. This type of analysis is now far more accessible.\n\nThe distribution of costs was also notable. The model with the most advanced reasoning capabilities accounted for 62% of the budget while processing only 7% of the tokens. Standard models handled most of the volume at a significantly lower cost.\n\nDeep analysis remains more expensive than broad coverage, but the difference is no longer large enough to represent a significant barrier.\n\nFor organisations developing critical software, the implication is clear: systematically reviewing an entire codebase in depth is now within reach of many more people and organisations.\n\nThe full report, including the methodology and a breakdown of costs by model, is available here: **What Can an Attacker Find With an LLM?**\n\n#CyberSecurity #ApplicationSecurity #LLM #SecureCodeReview #ISGroup", "url": "https://wpnews.pro/news/an-llm-assisted-security-review-of-globaleaks-41-findings-for-3140", "canonical_source": "https://www.isgroup.biz/en/cyber-security/llm-based-code-security-review-costs-findings-methodology.html", "published_at": "2026-07-30 18:16:01+00:00", "updated_at": "2026-07-30 18:22:03.692118+00:00", "lang": "en", "topics": ["large-language-models", "ai-tools", "ai-safety"], "entities": ["GlobaLeaks", "IS Group"], "alternates": {"html": "https://wpnews.pro/news/an-llm-assisted-security-review-of-globaleaks-41-findings-for-3140", "markdown": "https://wpnews.pro/news/an-llm-assisted-security-review-of-globaleaks-41-findings-for-3140.md", "text": "https://wpnews.pro/news/an-llm-assisted-security-review-of-globaleaks-41-findings-for-3140.txt", "jsonld": "https://wpnews.pro/news/an-llm-assisted-security-review-of-globaleaks-41-findings-for-3140.jsonld"}}