iFinder AI agents identify 84 vulnerabilities in 5G core implementations
Researchers at Nanyang Technological University developed iFinder, a multi-agent AI system that identified 84 vulnerabilities in open-source 4G and 5G core implementations. The findings demonstrate how agentic AI can automate security testing at machine speed, highlighting a critical gap between automated vulnerability discovery and manual remediation processes in cloud-native telecom infrastructure.
Key Takeaways
- Developers confirmed 83 of the 84 vulnerabilities found, with 81 receiving official CVE numbers.
- A session hijacking flaw was identified in the N4 interface between the Session Management and User Plane Functions.
- Five of the seven tested cores allowed valid SIM devices to tunnel control messages and reach internal interfaces.
- Despite the findings, 23 confirmed vulnerabilities currently lack a formal code fix or patch.
Why It Matters
The discovery of 84 flaws via automated agents signals a shift where vulnerability identification now moves at machine speed, far outpacing manual remediation cycles. For streaming infrastructure relying on 5G, this highlights a growing risk in cloud-native cores where internal interfaces are increasingly exposed through configuration errors or protocol tunneling. As these automated 'agent swarms' become more accessible, the industry must move toward automated defense loops to protect subscriber data sessions from hijacking. Watch for whether major telecom vendors integrate similar multi-agent testing into their CI/CD pipelines to close the gap between discovery and patching.
Additional Context
Nanyang Technological University's iFinder system enters a competitive field where telecom security testing is increasingly automated. In March 2025, the 3GPP Security Assurance Group published updated specifications for 5G core network security testing, establishing baseline requirements that open-source implementations like Open5GS and free5GC must meet before commercial deployment. Meanwhile, the OpenSSF launched its Alpha-Omega project targeting critical open-source infrastructure security, which directly funds security audits of projects that form the backbone of telecom and cloud-native stacks, including several 5G core implementations that AI agents uncover 84 5G core security vulnerabilities tested.
For related background, see StreamingMeme's prior coverage of Multiverse Computing launches Quasar 438B reasoning model for enterprise agents.
Read full article at sebastianbarros.substack.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source