read this bottom up and you have the actual ranking :)
Most AI cybersecurity benchmarks answer the wrong question for bug-bounty hunters.
They give the model source code, a known CVE, a vulnerability category, or a tightly framed objective.
That is useful for measuring security knowledge and white-box reasoning. But it is not how


