Capital One has open-sourced an internally developed AI-powered security tool called VulnHunter, designed to identify and fix software vulnerabilities at the code level. Unlike traditional scanners, it uses an agentic reasoning workflow to map attack paths, propose targeted code fixes, and reduce false positives that slow developer workflows. The company released it publicly on GitHub, citing the need for widely distributed defensive tools to address the interconnected risks of modern software supply chains.