Tag
Tailscale recounts how they tracked down a 16-year-old SQLite bug causing database corruption and outages, eventually fixing it after months of investigation.
Anthropic's Mythos AI model has been uncovering critical and important bugs in Microsoft's SharePoint and other software at a rate that outstrips Microsoft's ability to patch them, raising urgent security concerns about adversaries exploiting the same vulnerabilities.
Kimi K3 outperformed Fable/Opus 4.8 and GPT-5.6 Sol by finding 5 real bugs in a post-quantum cryptography project audit.
Researchers at Basis used LLMs to formally verify Linux's nftables firewall, discovering two critical bugs affecting all versions since 2022 and producing a verified implementation free of those bugs.
AI tool VEGA from Nebula Security discovered a 15-year-old use-after-free bug in the Linux kernel (GhostLock) that allows any logged-in user to gain root access. The flaw, present since 2011, was patched in April but rollout is uneven.
The author tests whether other AI models can match Mythos's exceptional ability to find security vulnerabilities, creating a benchmark of bugs found by Mythos and testing models like Opus. Initial results suggest Mythos may be uniquely powerful.
BugTraceAI Apex is a fully local 26B Mixture-of-Experts model fine-tuned via DPO for red teaming and bug hunting, trained on elite bug reports and evasion techniques. It runs on consumer GPUs via quantization.
AI-based security scanning has discovered 17 bugs in Perfetto's trace processor over 10 weeks, highlighting the potential for AI to uncover vulnerabilities in long-tail code that previously received little attention.
AI tools are accelerating the discovery and public disclosure of Linux kernel bugs, creating a worrisome trend of frequent privilege-escalation vulnerabilities that may require weekly server reboots. Linus Torvalds has changed how the Linux security community handles AI-discovered bugs, treating them as public by default.
Anthropic's new AI model, Claude Mythos, identified over 10,000 high and critical security flaws in global system software within a month, with a false positive rate better than human testers, significantly advancing AI-driven cybersecurity.
Linus Torvalds has declared the Linux security mailing list 'almost entirely unmanageable' due to an overwhelming number of duplicate AI-generated bug reports, calling the churn 'pointless work.'
Mozilla reports a significant increase in security fixes for Firefox in April after utilizing Claude Mythos to assist in bug hunting and hardening the browser.
Claude Code introduces /ultrareview, a cloud-based fleet of AI agents that automatically hunt for bugs before merging critical changes.
Mozilla used Anthropic’s Mythos Preview to automatically identify and fix 271 vulnerabilities in Firefox 150, signaling a major shift in how software security will be managed as AI-powered bug discovery becomes widespread.