← All speakers

Bio, Work & Ideas

David Brumley

Conference affiliation: Chief AI and Science Officer · Bugcrowd, Inc · 2026

On this page

David Brumley is Bugcrowd’s Chief AI and Science Officer, a Carnegie Mellon University professor, and co-founder of Mayhem Security, the autonomous cybersecurity company previously called ForAllSecure. His work addresses a foundational security problem: whether machines can discover real software vulnerabilities, prove they are exploitable, and evaluate increasingly sophisticated attacks reliably.

From incident response to autonomous security

Brumley studied mathematics at the University of Northern Colorado, earned a computer science master’s degree at Stanford University, and completed his doctorate at Carnegie Mellon. As a Stanford computer security officer from 1998 to 2002, he handled security incidents before pursuing automated vulnerability discovery as a research problem.

At Carnegie Mellon, his research has spanned binary program analysis, symbolic execution, automatic exploit generation, and reverse engineering. He previously directed the university’s CyLab security institute and founded picoCTF, a competition that introduces students to cybersecurity through progressively challenging hacking exercises. He also advises Carnegie Mellon’s competitive hacking teams and is a venture partner at Rain Capital.

In 2012, Brumley co-founded ForAllSecure with Carnegie Mellon researcher Thanassis Avgerinos. Their Mayhem system won DARPA’s 2016 Cyber Grand Challenge, an autonomous cybersecurity competition, earning the $2 million first prize. The company launched its commercial product in 2019 and subsequently became Mayhem Security. Brumley served as its chief executive until Bugcrowd acquired Mayhem in November 2025, combining automated security testing with human security researchers.

What makes automated hacking credible

  • Exploitation is a ladder of measurable capabilities. Triggering a crash does not establish that a system can compromise its target. Brumley evaluates harder milestones including arbitrary memory reads and writes, vulnerability chaining, sandbox escapes, and arbitrary code execution.
  • ExploitBench tests attacks against hardened software. Brumley and Seunghyun Lee created ExploitBench, which evaluates 16 exploitation capabilities across 41 vulnerabilities in V8, the JavaScript and WebAssembly engine used by Chrome. Their research measures exploit development from known vulnerabilities without conflating that capability with independent zero-day discovery.
  • Deterministic grading oracles demand executable proof. Reproducible, containerized security environments can verify crashes, memory access, and code execution directly. Program behavior determines success; another language model’s unsupported judgment does not.
  • Open-world vulnerability audits expose reward hacking. Single-bug benchmarks can train models to rediscover the easiest flaw repeatedly. Brumley instead asks systems to find multiple vulnerabilities, submit executable proofs, distinguish failures by their backtraces, and score results using precision and recall—including previously unknown bugs.

Brumley also writes for security leaders about the distinct risks of machine learning, symbolic reasoning, search, and hybrid architectures. His work on AI system security extends those concerns to training provenance, model supply chains, tool permissions, persistent memory, and autonomous agents.

Read the topics behind these talks

1 conference talk

References