Volcano Engine Unveils Agent Miner and BoardSentinel at Black Hat Asia 2026

At Black Hat Asia 2026 in Singapore, Volcano Engine showcased two AI security research projects—Agent Miner, a multi‑agent audit framework that discovered over fifteen vulnerabilities and earned seven CVEs, and BoardSentinel, an automated BMC firmware analysis system that dramatically speeds up large‑scale hardware security assessments.

ByteDance SE Lab
ByteDance SE Lab
ByteDance SE Lab
Volcano Engine Unveils Agent Miner and BoardSentinel at Black Hat Asia 2026

Agent Miner: Multi‑Agent Security Audit Framework

Agent Miner is a general‑purpose AI‑agent security audit framework built on a collaborative network of specialized agents. The framework decomposes an audit task into roles such as planning, static code analysis, and dynamic risk verification.

Static‑dynamic closed‑loop audit process:

Static analysis scans the target AI agent’s code to identify potential risk points.

A dedicated “risk‑verification officer” agent automatically generates proof‑of‑concept exploits for the identified points and executes them to confirm the threats.

Using this pipeline, Volcano Engine evaluated more than ten mainstream open‑source AI agents, discovered over fifteen security vulnerabilities, and obtained seven CVE identifiers.

BoardSentinel: Automated Static Analysis Framework for BMC Firmware

BoardSentinel automates the full analysis workflow for Baseboard Management Controller (BMC) firmware from vendors such as AMI MegaRAC and OpenBMC. The framework automatically unpacks, disassembles, and analyzes firmware binaries.

Hybrid vulnerability detection engine combines:

ID A Pro decompilation for low‑level code insight.

Semgrep pattern‑matching rules for known issue signatures.

Custom detectors for novel security risks.

The engine produces actionable reports that include remediation suggestions. The automation shortens the firmware analysis cycle, enabling large‑scale, rapid auditing of hardware‑level security risks.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

AI securityAgent MinerBlack Hat AsiaBMC firmwareBoardSentinel
ByteDance SE Lab
Written by

ByteDance SE Lab

Official account of ByteDance SE Lab, sharing research and practical experience in software engineering. Our lab unites researchers and engineers from various domains to accelerate the fusion of software engineering and AI, driving technological progress in every phase of software development.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.