security-research

Tag

Cards List
#security-research

Simcha Kosman AMA: Owning ChatGPT's Secure Sandbox

Reddit r/ArtificialInteligence · 5d ago Cached

Security researcher Simcha Kosman discusses his team's Black Hat USA 2026 research on breaking out of ChatGPT's secure sandbox, highlighting vulnerabilities in container isolation and AI supervision through attack chains.

0 favorites 0 likes
#security-research

The Vulnpocalypse Is Repricing the Bug Bounty Economy

Lobsters Hottest · 6d ago

The article discusses how a surge in cybersecurity vulnerabilities, referred to as 'Vulnpocalypse,' is leading to reevaluation and changes in the pricing structures of bug bounty programs.

0 favorites 0 likes
#security-research

Curvature Cryptanalysis of Smooth Transformer Feed-Forward Networks

arXiv cs.LG · 2026-09-01 Cached

The paper introduces a curvature-based cryptanalysis method to extract hidden feed-forward network structures in transformers using black-box queries, achieving high-fidelity functional model substitutes.

0 favorites 0 likes
#security-research

@dealignai: GLM-5.3 Uncensored NVFP4 + MTP Great for offensive cybersec (other harmful stuff complies fine) MMLU logit mode within …

X AI KOLs Timeline · 2026-08-29 Cached

Dealignai has released GLM-5.3 Uncensored NVFP4, an uncensored AI model designed for offensive cybersecurity tasks with refusal behavior removed at the weight level, capable of generating working security code while maintaining near-base performance.

0 favorites 0 likes
#security-research

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Wired · 2026-08-22 Cached

A WIRED article reports on multiple tech security issues, including a research finding that expired Visa cards can be exploited for contactless payments through a man-in-the-middle app, along with other stories on AI surveillance, privacy breaches, and encryption debates.

0 favorites 0 likes
#security-research

Remotely Unlocking Electric Scooters

Hacker News Top · 2026-08-21 Cached

A security researcher details the process of remotely unlocking electric scooters by performing reconnaissance on the company's web infrastructure and exploiting vulnerabilities in WordPress and an operations panel.

0 favorites 0 likes
#security-research

@MaxForAI: Just now, a paper that could shake the large model community was published! For the first time, researchers systematically “stole” the real hidden chain-of-thought on a large scale from OpenAI, Anthropic, and Google's closed-source models. Then, they went ahead and used these chains to study Kimi K3, GLM-5.2…

X AI KOLs Timeline · 2026-08-11 Cached

Researchers have, for the first time, systematically extracted hidden chain-of-thought from closed-source models at OpenAI, Anthropic, and Google. They exploited an API encryption compatibility flaw to have weaker models decrypt the content, thereby bypassing CoT distillation protections, and also studied open-source models such as Kimi K3, GLM-5.2, and DeepSeek.

0 favorites 0 likes
#security-research

@FAMASoon: https://github.com/hacksysteam/HackSysExtremeVulnerableDriver… UAF done

X AI KOLs Timeline · 2026-08-10 Cached

HackSys Extreme Vulnerable Driver (HEVD) is an intentionally vulnerable Windows kernel driver for learning kernel exploitation techniques, including use-after-free, stack overflows, and pool overflows. The tweet notes that a UAF exploit has been completed.

0 favorites 0 likes
#security-research

Crashing Through Defenses: Exploiting Segfaults and Chaining around Intel CET

Lobsters Hottest · 2026-08-09 Cached

This repository provides artifacts for Segmentation Fault-Oriented Programming (SFOP), a novel exploitation technique that abuses signal handlers to bypass Intel CET. It includes PoC exploits and demonstrations against Nginx and Ladybird.

0 favorites 0 likes
#security-research

Hardware backdoors in some x86 CPUs

Hacker News Top · 2026-08-08 Cached

Security researcher Domas reveals rosenbridge, a hardware backdoor in VIA C3 x86 CPUs that allows unprivileged code to bypass processor protections and access kernel memory. The repository provides tools to check for and mitigate the vulnerability.

0 favorites 0 likes
#security-research

@clearseclabs: Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models by @clearbluejar at DEF CON !

X AI KOLs Timeline · 2026-08-08 Cached

Announcement of a DEF CON talk by @clearbluejar on hands-on vulnerability discovery using local AI models.

0 favorites 0 likes
#security-research

AI-generated vulnerability patches require human review

Lobsters Hottest · 2026-08-06 Cached

Off-by-1 Labs (1Password) research finds that LLM-generated patches for complex, recently disclosed vulnerabilities are flawed 53.9% of the time, often failing to resolve the issue or introducing new vulnerabilities. The study emphasizes that AI-generated patches require human review and releases tooling, datasets, and a paper.

0 favorites 0 likes
#security-research

schrodingers-toctou: The binary you run is not the program you wrote

Lobsters Hottest · 2026-08-06 Cached

This research describes compiler-invented loads, where compiler optimizations create additional memory reads not present in source code, turning seemingly secure code into vulnerable binaries with TOCTOU races. It includes audits across kernels, hypervisors, enclaves, and firmware.

0 favorites 0 likes
#security-research

From your doorbell to your home network

Hacker News Top · 2026-08-05 Cached

A security researcher details how they reverse-engineered the Eufy Security Video Doorbell ecosystem, demonstrating jamming attacks, decoding the soundwave sync protocol, and extracting decrypted credentials from memory dumps.

0 favorites 0 likes
#security-research

@XAMTO_AI: A two-person security team used AI to find real vulnerabilities in code and earned $250,000 from a single bounty. Now they've open-sourced the system as Open-Kritt. It's not a toy that throws a repo at an AI to search blindly; it's an orchestration platform that turns AI agents into a small security team. Most people just hand an AI a…

X AI KOLs Timeline · 2026-08-02 Cached

Open-Kritt is an open-source security research platform that orchestrates multiple AI agents to analyze code in parallel, automating discovery of real vulnerabilities, and supports deduplication, validation, and prioritization. The team behind it has used it to earn significant bounties and win the Firedancer audit contest.

0 favorites 0 likes
#security-research

They Forgot What Happened Last Time: Hacking the Windows 365 Link [video]

Hacker News Top · 2026-07-31 Cached

A conference talk at EMF 2026 where researcher Rairii presents findings on hacking Microsoft's Windows 365 Link thin client, bypassing its locked-down 'secure-by-design' architecture including EFI Secure Boot and BitLocker.

0 favorites 0 likes
#security-research

@github: GitHub’s Bug Bounty Program is evolving to prioritize high-quality, high-impact research. Learn about our next chapter:…

X AI KOLs Following · 2026-07-26 Cached

GitHub is restructuring its bug bounty program to prioritize quality over quantity, introducing a permanent VIP program with higher payouts, restructured public bounties with static payouts, and raising signal requirements to reduce low-effort reports.

0 favorites 0 likes
#security-research

Cynative Security Research Agent

Product Hunt · 2026-07-23

Cynative Security Research Agent lets users query their cloud infrastructure safely without impacting production.

0 favorites 0 likes
#security-research

PlanFlip: Attacking Multi-Agent LLM Systems via Planning-Phase Prompt Injection

arXiv cs.AI · 2026-07-21 Cached

This paper identifies the planning phase in multi-agent LLM systems as a critical attack surface, introducing PlanFlip—a framework of four planning-phase prompt injection attacks that achieve cascade amplification across downstream agents. Evaluations on nine frontier LLMs reveal that stronger models like GPT-5 are more vulnerable, while reasoning-augmented models like DeepSeek-R1 resist attacks, and proposed defenses achieve high detection rates.

0 favorites 0 likes
#security-research

A Linux Kernel 0-day Journey - From a limited UAF to Physical Memory R/W

Lobsters Hottest · 2026-07-20 Cached

This article details the discovery and exploitation of a Linux kernel 0-day vulnerability in the network scheduler subsystem (red scheduler), turning a limited slab use-after-free into full physical memory read/write, ultimately achieving privilege escalation to root. The vulnerability existed for 2.5 years and was fixed in June 2026.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback