What it is
XGPT is ThreatBook’s security-focused generative AI service. Public product material describes security analysis and completion capabilities, while affected-project records now provide exact vulnerability-level credits.
What is verified
Apple directly names researchers using XGPT on four CVEs spanning the kernel, SMB, and Libnotify. Libseccomp’s public release material credits Feng Xue with XGPT on three fixed GHSA-only findings. A separate NGINX CVE is retained for a historical backfill because F5/NGINX directly credits the same collaboration.
Bugflation does not count ThreatBook posts where XGPT detected exploitation of an already-known vulnerability; detection is not discovery.