Introducing Project Red: Autonomous Vulnerability Reproduction

Today, watchTowr is launching Project Red: an AI-powered, fully autonomous vulnerability reproduction capability built into the watchTowr Platform.

Project Red has been operational inside the watchTowr Platform for the last few months, reproducing emerging vulnerabilities autonomously so client exposure can be validated at attacker speed, keeping pace with AI-assisted attackers and their increasingly fast in-the-wild exploitation timelines.

One recent example shows how quickly this now moves. Last week, when wp2shell (CVE-2026-63030) dropped, Project Red reproduced the vulnerability in 22 minutes. AI-Driven Rapid Reaction used that reproduction to validate client exposure, and Active Defense deployed autonomous mitigation shortly after, all before in-the-wild exploitation began.

This post explains what Project Red is, how it works, and why it was built.

The problem Project Red was built to solve

Exploitation is happening faster, and at greater scale. The time between a vulnerability being disclosed and exploited in the wild is now measured in hours, and AI-driven exploitation will continue to compress it further.

At the same time, the volume of vulnerabilities keeps climbing, with thousands disclosed every year and the attack surface widening alongside them.

watchTowr is already consistently the fastest in the industry to rapidly react to emerging threats. Reproducing a vulnerability is the first step in that reaction: before exposure can be validated, the vulnerability has to be reproduced from the information available, including patches, vendor advisories, and product changes.

Project Red is how watchTowr scales that step. By leveraging AI to reproduce vulnerabilities autonomously, Project Red increases the speed and scale at which watchTowr reacts, keeping pace with both faster exploitation and a growing volume of vulnerabilities.

That is what Project Red was built to do: deliver autonomous vulnerability reproduction at attacker speed, at the scale the threat landscape now demands.

What is autonomous vulnerability reproduction?

Project Red is watchTowr’s AI-powered, fully autonomous vulnerability reproduction capability. When a new vulnerability emerges, Project Red uses AI to reproduce it autonomously, without human reverse engineering and without waiting on a published CVE.

Reproduction is the input to everything that follows. Project Red does not validate exposure itself. It produces a working, reproduced vulnerability that AI-Driven Rapid Reaction then uses to validate which clients are actually exposed.

How Project Red works

The moment a new vulnerability surfaces, Project Red goes to work as an autonomous vulnerability reproduction pipeline.

  • Identifies an emerging threat. watchTowr’s threat intelligence feeds and continuous monitoring of social and open sources flag an emerging vulnerability.
  • Works out what changed. Where a fix exists, such as a patch to an open source project, Project Red uses AI to analyze it and pinpoint exactly what the vendor changed.
  • Understands the vulnerability. From that change and the context around it, Project Red builds an understanding of the underlying flaw.
  • Reproduces and proves exploitability. Project Red reproduces the vulnerability and builds a safe, non-destructive check that proves exploitability without impact.
  • Proves the reproduction in the lab. The check runs against both the unpatched and patched versions, demonstrating the vulnerability has been reproduced genuinely and reliably rather than assumed.
  • Confirms safety through CI/CD. A hardened CI/CD process validates the safety of the reproduced exploit before it goes any further.
  • Passes under human review. Before anything reaches production, watchTowr researchers review the output to confirm nothing is amiss.

Within that same process, the reproduced vulnerability is used by AI-Driven Rapid Reaction to validate which clients are exposed.

When wp2shell dropped last week, this entire process completed in 22 minutes.

Already integrated into the watchTowr Platform

Project Red is not a standalone product, and it is available to clients today. watchTowr is already using it to rapidly react to emerging threats faster than ever.

It works in tandem with AI-Driven Rapid Reaction and Active Defense, and together these capabilities allow the watchTowr Platform, watchTowr’s Preemptive Exposure Management platform, to deliver autonomous vulnerability reproduction, autonomous validation of exposure, and autonomous mitigation as a single system:

  • Project Red autonomously reproduces the threat.
  • AI-Driven Rapid Reaction autonomously validates exposure against it.
  • Active Defense autonomously mitigates at the edge, buying time to remediate on the organization’s own schedule, not under the pressured chaos of an incident.

This is what becomes possible when AI combines reproduction, validation, and mitigation into a single system operating at attacker speed.

By combining Proactive Threat Intelligence, External Attack Surface Management, and Autonomous Mitigation, the watchTowr Platform gives security teams the one thing they need most: time to respond.

Preemptive Exposure Management, built to outpace attackers.

Book a demo to see how Project Red powers the watchTowr Platform.

Related Posts

Preemptive Exposure Management gains momentum as organizations confront faster-moving threats SINGAPORE and LONDON and NEW YORK, June 02, 2026 (GLOBE

The 2026 Verizon DBIR analyzed over 22,000 breaches and confirmed vulnerability exploitation is now the most common initial access vector.

Every organization faces a fundamental question about its security posture: does it actually work? Not whether the right tools are

Gain peace of mind, with always-on, 
continuous testing.