NEWS

-

サービス

AGEST ZERO SHIELD INSIGHTS

Home

keyboard_arrow_right

AGEST Commences PoC for Com...

AGEST Commences PoC for Commercialization of “Autonomous AI-Driven Comprehensive Cybersecurity Platform “AGEST ZERO SHIELD”” Co-Developed with US-Based Lazarus

AGEST, Inc. (Headquarters: Bunkyo-ku, Tokyo; Representative Director, President, Executive Officer, and CEO: Yasumasa Ninomiya; hereinafter “the Company”), which supports the improvement of software quality and safety utilizing advanced quality technology, will commence a Proof of Concept (PoC) from the end of July 2026 toward the commercialization of the “Autonomous AI-Driven Comprehensive Cybersecurity Platform” co-developed with U.S.-based Lazarus Enterprises, Inc. (hereinafter “Lazarus”), as announced on June 10, 2026.

Recent Challenges Corporate/Organizational Cybersecurity Trends and

With the emergence of advanced AI frontier models, exemplified by the recently announced “Claude Mythos Preview” (hereinafter “Mythos”) *1, the environment surrounding cybersecurity is undergoing significant changes, including the sophistication of both AI-driven attacks and defenses.

From the defensive perspective of companies and organizations, continuously strengthening defensive capabilities against these new cyber threats has become a critical management issue underpinning business continuity and corporate trust.

On the other hand, security measures utilizing advanced AI models entail challenges such as:

  • External transmission risk of source code via APIs (data sovereignty concerns)

  • Heavy token billing burdens due to a rapid increase in traffic, such as increased full-scan opportunities

  • Condition hurdles for utilizing frontier AI models like Mythos, as well as the risk of sudden service suspension due to export regulations, etc.

  • The need to respond to high-speed and high-frequency alerts, leading to alert fatigue risks

Furthermore, while attackers utilize advanced AI, defensive entities such as companies and organizations are hindered by multiple layers of safety measures (guardrails). This creates a concern regarding an asymmetry where code verification from an attacker’s perspective cannot progress through legitimate procedures.

About “AGEST ZERO SHIELD” and the Start of the PoC

To continuously resolve these challenges, the Company has co-developed the “Autonomous AI-Driven Comprehensive Cybersecurity Platform ‘AGEST ZERO SHIELD'” with Lazarus. As the first phase, we are preparing for the commercialization in September 2026 of the “Zero-Day Vulnerability Hunting” feature, which includes zero-day vulnerability detection similar to frontier AI and a function to propose patches or code fixes for discovered vulnerabilities.

Features of ‘AGEST ZERO SHIELD’

  • Can be utilized while ensuring data sovereignty through installation in on-premises/closed-network environments.
    * Unlike frontier AI, source code is not transmitted to overseas companies.

  • An annual fixed-fee license system, not token-based.

  • Planned continuous version upgrades for AI models specifically specialized in cybersecurity.

Additionally, it boasts high vulnerability hunting capabilities achieved through a proprietary harness and LLM tuning by Lazarus and the Company.

In our verifications, it has successfully discovered vulnerabilities such as the “FFmpeg H.264 slice counter vulnerability” *2 (also cited as an example by Mythos), as well as previously undiscovered vulnerabilities, such as the following examples.

CVE

Anthropic CVE

Date

CVSS

Lang

Explanation

CVE-2026-28208

ANT-2026-9VJ9JJXQ

2026/2/26

5.9

Java

Junrar has arbitrary file write due to backslash path traversal bypass in LocalFolderExtractor on Linux/Unix

CVE-2026-32316

ANT-2026-EBDTPNVH

2026/4/13

7.5

C

jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow

CVE-2026-40034

ANT-2026-6SNS6KMP

2026/5/26

7.3

Rust

gitoxide – Command Injection via Partial .gitmodules Override in gix-submodule

CVE-2026-27775

-

2026/7/3

8.8

Go

Gitea pre-receive hook permission cache allows full repository write access

CVE: CVE (Common Vulnerabilities and Exposures) is a universal identification number assigned to publicly known security vulnerabilities (flaws) in systems and software.
ANT CVD: Coordinated Vulnerability Disclosure (CVD) identification number, a system for properly fixing and publishing vulnerabilities. When Anthropic discovers a vulnerability, an ANT identifier is assigned, though it may not always be published as standalone vulnerability information.
*CVSS: CVSS (Common Vulnerability Scoring System) is an international industry standard metric that quantifies the severity of security vulnerabilities in information systems and software on a scale of 0.0 to 10.0. A higher score indicates a higher risk level, and it is utilized by organizations to prioritize vulnerability responses.
Exploit Chain Context: In recent years, a cyberattack method known as an “Exploit Chain” has emerged, where attackers sequentially chain execution of attack codes against multiple vulnerabilities (security holes) to achieve an ultimate goal, such as seizing control of a system. Even if individual vulnerabilities present a low-level threat on their own, cleverly combining them has revealed attack methods that can ultimately hijack privileges at the deepest levels of a system. Consequently, threat levels can no longer be judged solely by CVSS scores.

■Flow of Zero-Day Vulnerability Hunting

Flow of Zero-Day Vulnerability HuntingEach process is looped multiple times to suppress hallucinations and ensure improved
reproducibility.

■Image of the Vulnerability Detection Screen

脆弱性検知実例画面To introduce these results into actual customer environments and conduct various verifications toward commercialization, the Company will commence PoCs from the end of this month with partner companies, centered around major domestic SIers with whom we have been in discussions.

Future Initiatives

Having received numerous inquiries from various companies, we have already closed the application period for this upcoming PoC. Moving forward, we will engage in ongoing discussions regarding the execution of this PoC and its commercialization, and proceed with the construction of a partnership ecosystem with deployment consulting partners and hardware procurement partners to widely promote the introduction of “AGEST ZERO SHIELD.”

Details such as the commercialization schedule and additional features will be publicly announced in due course.

Planned Additional Features

  • Live target monitoring function (equivalent to CNAP)

  • Detection of security breaches through log analysis of live targets

  • Autonomous AI penetration testing

  • Offensive cyber control functions

1: An advanced AI model provided on a limited basis by Anthropic, particularly a frontier model specialized in the cybersecurity domain, such as zero-day vulnerability detection, vulnerability analysis, and attack path generation.
2: As a result of Project Glasswing, this detected a vulnerability that had laid hidden in
the FFmpeg H.264 slice counter for 16 years (An issue called “h.264 slice counter
mismatch or 0xFFFF sentinel collision”, for which no CVE number has been issued).

2026/07/23

  • 杵島 直樹

    Kijima Naoki

    特定助教

    デジタル教材自動生成、パーソナライズ学習支援、生成AI応用

  • Rafael Gonzalez

    Rafael Gonzalez

    客員研究員

    機械学習、人工知能、適応型学習システム

  • Lisa Han

    Lisa Han

    客員研究員

    クロスカルチュラル教育、教育社会学、比較教育学

  • 佐伯 美咲

    Saeki Misaki

    博士課程3年

    教育心理学、認知負荷理論、学習動機付け

  • 鷹見 陽大

    Takami Haruto

    博士課程2年

    教育データマイニング、ラーニングアナリティクス、行動分析

  • 小林 颯

    Kobayashi Hayate

    博士課程1年

    教育用VR/AR、没入型学習環境、メディア教育

  • 中村 翔太

    Nakamura Shota

    修士課程2年

    ゲーミフィケーション、教育アプリ開発、ユーザー行動分析

  • 結城 るか

    Yuuki Ruka

    修士課程2年

    HCI、UXデザイン、感情応答インタフェース

  • 加藤 玲奈

    Kato Reina

    修士課程1年

    学習分析、データビジュアライゼーション、教育評価

  • 松田 真紀

    Matsuda Maki

    研究室秘書

    研究支援、イベント運営、広報サポート

お問い合わせ

デモのリクエスト、ご相談はこちらよりお寄せください。

お問い合わせはこちら