<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://divd-nl.github.io/feed.xml" rel="self" type="application/atom+xml" /><link href="https://divd-nl.github.io/" rel="alternate" type="text/html" /><updated>2026-05-07T09:50:27+00:00</updated><id>https://divd-nl.github.io/feed.xml</id><title type="html">Project Lacewing</title><subtitle>A European, open, community-driven answer to AI-driven vulnerability research. By DIVD.</subtitle><entry><title type="html">Launching Project Lacewing: a European answer to AI-driven vulnerability research</title><link href="https://divd-nl.github.io/blog/2026/05/07/project-lacewing-launches/" rel="alternate" type="text/html" title="Launching Project Lacewing: a European answer to AI-driven vulnerability research" /><published>2026-05-07T00:00:00+00:00</published><updated>2026-05-07T00:00:00+00:00</updated><id>https://divd-nl.github.io/blog/2026/05/07/project-lacewing-launches</id><content type="html" xml:base="https://divd-nl.github.io/blog/2026/05/07/project-lacewing-launches/"><![CDATA[<p>Today is day one of Project Lacewing.</p>

<p>A month ago, Anthropic launched Project Glasswing — a large-scale initiative using AI to find and fix vulnerabilities in critical software. The ambition is real, and the technology is genuinely impressive. But the initiative is shaped by a small group of American technology companies and investors, and after the preview period, access to the underlying model comes at a cost that puts it out of reach for most of the world.</p>

<p>We think Europe deserves its own answer. Independent. Non-profit. Transparent. Driven by the security community, not by commercial interest.</p>

<p>That answer is Project Lacewing.</p>

<h2 id="what-we-are-building">What we are building</h2>

<p>Project Lacewing uses AI to find and fix vulnerabilities in critical software — at a scale and speed that DIVD’s volunteer researchers could not reach alone. Everything we find will be disclosed responsibly, as it always has been: the affected party first, then the world.</p>

<p>The project is organised into focused sub-projects, each with a clear scope:</p>

<ul>
  <li><strong>Project Initiation</strong> — building the partner ecosystem and defining the roadmap. Active now.</li>
  <li><strong>Open Source Models</strong> — investigating how well open source AI models perform on vulnerability research tasks, so we are not permanently dependent on commercial providers.</li>
  <li><strong>Closed Source Models</strong> — independently evaluating the claims commercial providers make about their models’ capabilities. We will publish the results openly, whatever they show.</li>
  <li><strong>Investigation of Software</strong> — AI-assisted vulnerability research on critical software that commercial initiatives are unlikely to prioritise.</li>
  <li><strong>Data Leak Discovery</strong> — automated detection of sensitive data unintentionally exposed in cloud storage buckets and source code repositories.</li>
  <li><strong>Vulnerable Configuration Research</strong> — automated discovery of common misconfigurations in internet-facing systems before attackers find them first.</li>
</ul>

<h2 id="who-is-already-involved">Who is already involved</h2>

<p>DIVD provides the organisational backbone, the volunteer network, and the responsible disclosure infrastructure that makes this possible. We are proud to be joined from day one by <a href="https://www.lacewing.nl/partner/schuberg-philis/">Schuberg Philis</a> — a Dutch IT company specialising in mission-critical systems — as our first external partner.</p>

<p>We are actively looking for more: organisations that can contribute funding, hardware, people, or codebase access. The internet’s defence belongs to everyone. So does building it.</p>

<h2 id="read-more">Read more</h2>

<p>For the full background on why we launched Project Lacewing, the urgency behind it, and how to get involved, read our <a href="/docs/press_release_project_lacewing_launch/">press release</a> or explore the <a href="/projects/">sub-projects</a> on this site.</p>

<p>If you want to contribute — as a technical expert, a fundraiser, or a champion — <a href="mailto:lacewing@divd.nl">get in touch</a>.</p>

<p>The internet belongs to everyone. Let’s make sure its defence does too.</p>]]></content><author><name>DIVD</name></author><summary type="html"><![CDATA[Today DIVD launches Project Lacewing — a European, open, non-profit initiative to use AI for vulnerability research. Here is why we built it, and what we are going to do.]]></summary></entry></feed>