Case Study: Xint.io

Vulnerability Disclosure Drives Significant Media Coverage for Xint.io
Responsible disclosure of Copy Fail Linux vulnerability drives more than 100 articles across media landscape

Campaign Results
100+
Articles
20+
Tier 1 Placements
183M+
Estimated Reach
The Challenge
With little runway, Voxus PR worked quickly to manage a major zero-day Linux vulnerability disclosure by Theori and Xint.io.
With the rise of AI-native pentesting (and new LLMs like Mythos and GPT Cyber), the vulnerability disclosure game changed overnight. The research team at Theori and Xint.io responsibly disclosed a new zero-day for Linux source code called Copy Fail that allowed an unprivileged local attacker to gain root permissions on any Linux kernels released since 2017. This is one of the first major zero-day discoveries driven primarily by autonomous AI pentesting and had gone undiscovered for nearly a decade.
Due to coordination efforts, Voxus was unable to provide the media with any advanced notice of the disclosure (and was only informed of the release timeline days before it happened). As a result, the team had to coordinate a massive media blitz on disclosure day to security and Linux/open-source press. This included explaining to press the severity of the exploit, how it worked, what it allowed attackers to accomplish, and more. The team then had to coordinate in real-time, media requests for interviews and email commentary.


Highlights
Helped drive more than 100+ articles on disclosed vulnerability.
Landed more than 20 tier-1 security, technology and business articles in outlets including TechCrunch, ZDNet, Dark Reading, The Register, The Hacker News, SecurityWeek, BleepingComputer, SC Magazine, Cyber Security News, Hackaday, The Verge, Tom’s Hardware, Forbes, PCWorld, and more.
Secured additional podcast interview such as Risky Business.

Xint.io is the award-winning autonomous pentesting platform built by the security researchers at Theori, the most decorated team of white hat offensive security researchers in the world. Xint offers both black-box as well as white-box pentesting with results in less than 12 hours, including: full trigger conditions and step-by-step reproduction pathing, exploit impacts, and suggested remediations so teams can quickly triage and patch the most critical vulnerabilities. Xint is working with organizations with the highest defensive security needs, including DARPA and Samsung.
Featured In
Voxus drove broad coverage across the security and business media landscape.