DARPA Selects Xint to Use AI in Securing Military Messaging Apps

The Defense Advanced Research Projects Agency (DARPA) selected Xint to research the use of autonomous AI application security for deep analyses of internally and externally developed messaging applications that are used throughout the Department of War.

DARPA was established in 1958 following the USSR’s launch of Sputnik in 1957. The purpose was to ensure the US would never again be surprised by the technological achievements of foreign countries. DARPA consequently partners with and supports private industry in the development of cutting edge new technology to keep the US ahead of rivals.

This is a big deal for Xint. Previous DARPA engagements with private industry have led to the development of the internet (via ARPANET), GPS and Siri.

Xint (which emerged within Theori) was selected following its performance (it was one of the three winners) in DARPA’s Artificial Intelligence Cyber Challenge (AIxCC), a two-year, $29.5 million competition. It is now tasked with analyzing source code, whether internally developed by messaging apps such as Signal or open source projects. It will also analyze compiled binaries using a new service launched in September 2026. The service is designed to assess software supply chain risk across compiled code running in environments such as agents, on-premises software, appliances, network daemons, and other services.

“Messaging and communications applications are unique in that an attacker needs read-only access to compromise the entire point of the app,” said Andrew Wesie, CTO and co-founder at Xint. “Third-party SDKs and libraries embedded in these apps can create hidden data risks, where even seemingly minor leaks may expose a user’s location or other personally identifiable information during sensitive communications – often without the user or even the developer knowing.”

He explained Xint’s operation to SecurityWeek. DARPA is seeking to ensure that Department of War messaging is secure against external, and especially foreign, eavesdropping. Xint technology, using the latest frontier LLM models (he describes Xint as “really just a harness and a workflow around frontier elements”) is able to examine all the source code involved in the apps concerned, reverse engineering binaries as necessary. So, for messaging from Android, Xint would look at the app itself, the Linux kernel, and any other components of the Android ecosystem that sit between the app and the kernel. 

Advertisement. Scroll to continue reading.

Having access to every aspect of the system being analyzed, it can then detect and investigate any vulnerability across the entirety of the attack surface, automatically triage the vulnerabilities based on accessibility to an attacker, and then generate patches for any vulnerability that could be useful to attackers.

From this, DARPA gets the ability to secure War Department communications, while Xint retains a technology that can be applied to any system or application for any commercial customer, partly but not completely, funded by DARPA – and the US receives a technology that maintains its position at the cutting edge of innovation.

“Right now,” continued Wesie, “we’re talking to customers that have written their own code, such as a web app. We want to help them secure that code.” This security is offered as a SaaS solution. The developer is invited to run the code through Xint before its release to be vulnerability-free and then run additional regular scans to detect any new vulnerabilities introduced after the initial release.

Xint is continuing to evolve its service. “There are some enterprises that are interested in running everything within their own data center because they don’t want any of their source code leaving that data center,” said Wesie.” That’s still a work in progress, mainly because we won’t be able to use the latest OpenAI models, the latest Anthropic models – we cannot automatically use the latest LLM models and keep everything within a customer’s data center.”

Xint is already in use with customers. “Our relationship with and funding from DARPA is allowing us to continue developing additional capabilities. There is always more we can do.” Meanwhile, the DARPA / Xint relationship is a major confirmation of the synergy of cooperation. DARPA gets secure messaging for the Department of War, Xint gets a major commercial opportunity, and the market gets an opportunity for increased security.

Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

Related: Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Related: Critical WordPress Vulnerability Exploited Immediately After Disclosure

Related: Critical F5 BIG-IP Vulnerability Exploited as Zero-Day