cd /news/artificial-intelligence/code-review-used-to-be-the-only-way-… · home topics artificial-intelligence article
[ARTICLE · art-87617] src=helpnetsecurity.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Code review used to be the only way to catch these bugs

Palo Alto Networks' Unit 42 researchers built an automated system called NOVA that scanned the source code of 3,915 open-source projects over two months, identifying 14,090 vulnerabilities, each confirmed through its validation pipeline. Only 85 findings matched previously documented vulnerabilities, with most of those published two to eight weeks after NOVA's detection, suggesting the system can uncover bugs earlier than traditional code review.

read1 min views1 publishedAug 5, 2026

An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system’s validation pipeline. Vulnerability researchers at Palo Alto Networks’ Unit 42 built the system and checked its output against the public record afterward. Only 85 findings matched anything already documented, and most of those were published two to eight weeks after NOVA had found them. The count is … More

The post Code review used to be the only way to catch these bugs appeared first on Help Net Security.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @palo alto networks 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/code-review-used-to-…] indexed:0 read:1min 2026-08-05 ·