# GlobaLeaks Says 29 Vulnerabilities Fixed After AI-Assisted Audit

> Source: <https://letsdatascience.com/news/globaleaks-remediates-29-findings-from-ai-assisted-audit-3545df8c>
> Published: 2026-07-31 13:02:24+00:00

# GlobaLeaks Remediates 29 Findings From AI-Assisted Audit

GlobaLeaks published on July 30, 2026, the results of an AI-assisted security assessment that identified 29 confirmed vulnerabilities, 12 denial-of-service observations, and hardening recommendations. According to GlobaLeaks, two findings were rated High severity, none was critical, and confirmed vulnerabilities were remediated beginning with version 5.0.96. ITSecurityNews reports that the LLM-assisted review used roughly $3,140 in API calls.

GlobaLeaks has published the results of an independent AI-assisted security assessment that identified **29 confirmed vulnerabilities**, **12 denial-of-service observations**, and additional hardening recommendations. According to GlobaLeaks, the review was conducted by ISGroup between June 1 and June 30, 2026, alongside contributions from community members and users.

The organization reports that most findings were rated Low or Informational, with two High-severity issues and no critical vulnerabilities. The confirmed issues involved account-protection mechanisms, whistleblower anonymity protections, tenant isolation, audit-log completeness, and service availability under particular conditions.

GlobaLeaks states that the assessment examined a development snapshot captured during an intensive hardening cycle. It reports that all identified issues have since been addressed, with remediation of confirmed vulnerabilities beginning in **version 5.0.96**, released June 24. The latest stable release is version 5.0.99, according to the organization.

### Cost and coverage claims

ITSecurityNews, which indexed a Security Affairs article on the assessment, reports that the LLM-assisted review cost roughly **$3,140 in API calls**. The same report describes GlobaLeaks as a mature whistleblowing platform that had undergone six independent professional audits over the preceding 13 years.

GlobaLeaks characterizes the audit as a combination of human expertise and AI-assisted code analysis that enabled greater speed and coverage in the review. The organization also states that LLMs can enable exhaustive code analysis at a scale that was previously impractical.

### What the assessment illustrates

The reported result does not establish that an LLM independently found every issue or that the approach can replace conventional penetration testing. The published account instead describes an assessment that paired human security expertise with AI-supported code review, while also incorporating community contributions.

For security engineering teams, comparable workflows can make broad codebase triage and hypothesis generation less expensive than fully manual review. They still require human validation, severity assessment, exploitability testing, and remediation verification, particularly for systems handling anonymity, multi-tenant isolation, or sensitive disclosures.

The GlobaLeaks findings also illustrate a practical limitation of vulnerability counts: the security importance of a review depends on severity, affected components, reproducibility, and patch status, not only on the number of findings. In this case, GlobaLeaks reports that no critical vulnerability was identified and that the confirmed issues were remediated in released software.

## Key Points

- 1GlobaLeaks reported 29 confirmed vulnerabilities and 12 denial-of-service observations, with two High-severity findings and no critical issues.
- 2The assessment combined ISGroup's security review with AI-assisted code analysis, illustrating a human-validated approach rather than autonomous vulnerability discovery.
- 3Comparable LLM review workflows can expand code triage coverage, but human exploit validation and patch verification remain essential security controls.

## Scoring Rationale

The assessment offers a concrete, recent example of LLM-assisted source-code review applied to a mature security-sensitive open-source platform. It is relevant to application-security and ML practitioners evaluating AI-supported audit workflows, though it is not a broadly released model, tool, or benchmark.

## Sources

Public references used for this report.

Practice interview problems based on real data

1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.

[Try 250 free problems](/problems)
