NDAY Security, an NVIDIA Inception Member, Discloses Cyber-Physical Device Vulnerabilities Using Non-Frontier AI Models
Research cost under $100 and 36 hours and required no frontier AI models; details withheld pending coordinated
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
Research cost under $100 and 36 hours and required no frontier AI models; details withheld pending coordinated disclosure
MIAMI, FL, UNITED STATES, September 17, 2026 /EINPresswire.com/ — NDAY Security today disclosed a class of 53 exploitable weaknesses in widely deployed devices that operate in over an estimated 100 millions people’s homes and offices globally.
NDAY is not naming the vendor or product line. The company has entered the vendor’s coordinated disclosure process and is withholding technical details, proof-of-concept code, and affected models until a remediation is available.
Where conventional vulnerabilities cost organizations data, weaknesses in this class have physical consequences. The failure modes fall into the same category of risk that drew public attention after the Vault 7 disclosures in March 2017, which showed that ordinary appliances could be turned against the people.
What has changed since 2017 is not the nature of the risk but who can reach it. The complete research effort, from hypothesis through validated exploitation in a controlled lab, cost less than $100 and required no frontier AI models, specialized hardware, or privileged vendor documentation.
“We did not need a frontier model to find this. We used small, free or more affordable available models and commodity tooling, and the total spend was under a hundred dollars. The capability that reaches items people stand next to, and use both at work and home is no longer scarce and it is no longer expensive — and that is a different problem than the one most security programs are budgeted for.” —Michael McCord, AI Advisor, NDAY Security
Capability is not gated behind the frontier labs
The finding undercuts a common assumption: that AI-enabled offensive capability is concentrated in large frontier models, and therefore constrained by the safeguards those providers enforce.
Adversaries are not waiting for authorized access. They replicate offensive capability by whatever route is open, increasingly by turning widely available AI models to a single purpose, no frontier systems required. NDAY Security can speak to that reality directly, because the same class of technique is what powers AttackBench, the company’s autonomous penetration testing agent. The difference between AttackBench and adversary tooling is not capability. It is authorization, scope, and accountability. AttackBench operates only against systems customers own or are permitted to test, with verified results and a complete audit trail. The capability gap that many organizations are counting on no longer exists. The accountability gap does, and that is the one NDAY was built to close.
Coordinated disclosure
NDAY reported its findings to the vendor and is following the vendor’s published disclosure process. A full technical advisory, including affected versions and mitigation guidance, will publish at the conclusion of that process.
About NDAY Security
NDAY™ Security specializes in offensive security — identifying known vulnerabilities before they become liabilities. Founded by Mark Whitehead and John Cartrett, who have conducted and overseen tens of thousands of penetration tests over two decades, NDAY combines expert-led testing with generative AI to simulate the attack schemes of today’s threat actors. NDAY Security is a member of NVIDIA Inception Program.
PR
NDAY Security, Inc.
email us here
Legal Disclaimer:
EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
![]()
Media gallery
