This is the side of cybersecurity that policy-classifiers forbid, because it’s not really dual-use, only bad use
One exception where it’s useful for defensive purposes: if an AI model claims to have found a vulnerability in a codebase, a proof of concept is an efficient demonstration that the claimed vulnerability is legit. See also here.
One exception where it’s useful for defensive purposes: if an AI model claims to have found a vulnerability in a codebase, a proof of concept is an efficient demonstration that the claimed vulnerability is legit. See also here.