Tag
This paper identifies the planning phase in multi-agent LLM systems as a critical attack surface, introducing PlanFlip—a framework of four planning-phase prompt injection attacks that achieve cascade amplification across downstream agents. Evaluations on nine frontier LLMs reveal that stronger models like GPT-5 are more vulnerable, while reasoning-augmented models like DeepSeek-R1 resist attacks, and proposed defenses achieve high detection rates.
This article details the discovery and exploitation of a Linux kernel 0-day vulnerability in the network scheduler subsystem (red scheduler), turning a limited slab use-after-free into full physical memory read/write, ultimately achieving privilege escalation to root. The vulnerability existed for 2.5 years and was fixed in June 2026.
Pillar Research found sandbox escape vulnerabilities in AI coding agents from Cursor, Codex, Gemini CLI, and Antigravity, revealing that these agents can write files that host components later trust, bypassing sandbox boundaries. The findings highlight the need for a new threat model for agentic security.
Security researcher uses GPT5.6 Sol Ultra to discover a WordPress pre-auth RCE vulnerability, potentially worth $500k to exploit brokers, demonstrating AI's capability in cybersecurity research.
Qwythos-9B is a 9B super reasoning model based on the Qwen3.5-9B base, further trained with 500 million+ Claude Mythos reasoning traces. It natively supports 1M long context and tool calling, designed for local deployment by security researchers. It significantly outperforms the original base model on MMLU and mathematical reasoning.
A collection of cybersecurity datasets for machine learning and model training, covering network traffic, malware, web attacks, phishing, and more, including notable public research datasets like LANL, CTU-13, and UNSW-NB15.
Security researcher Ian Carroll used Anthropic's Claude AI to discover a vulnerability in Front Gate Tickets' system, allowing potential access to millions of records and free ticket issuance for major US music festivals. The flaw was patched within 24 hours with no evidence of exploitation.
The author tested a local AI model (Qwen 3.6 27b) for security research and found it surprisingly effective, outperforming other approaches like Semgrep and cloud AI agents in finding a PHPIPAM LFI vulnerability.
An anonymous GitHub account has released a large collection of proof-of-concept exploits for undisclosed 0-day vulnerabilities in numerous popular software packages, including 7zip, Docker, Firefox, FFmpeg, Ghidra, libssh2, Nmap, PHP, and VLC.
Satoshi Tanda announces his public Hypervisor Development class for security researchers, scheduled for Oct 12-15, 2026.
DeepSeek-V4-Fable is a distilled variant of Claude-5-Fable built on DeepSeek-V4-Flash, designed for autonomous offensive security research, CTF problem solving, and controlled environment exploitation planning, with strict authorization requirements.
This paper details a novel bootROM vulnerability in Apple A12/A13 SoCs, exploiting a hardware bug in the USB controller and a configuration flaw to achieve boot-chain compromise. A proof-of-concept is provided.
A detailed technical guide on discovering and exploiting misconfigured IIS servers for bug bounty hunting, covering techniques like Shodan queries, tilde enumeration, web.config exploitation, and WAF bypass.
The US government blocked Anthropic's Fable 5 and Mythos models after researchers used a simple 'fix this code' prompt, but security expert Katie Moussouris argues this was not a jailbreak and that the export controls harm cybersecurity defenders.
Amazon's cybersecurity research led to a White House directive banning foreign nationals from using Anthropic's Fable 5 and Mythos 5 models, sparking debate over whether the findings constitute a jailbreak.
Open-source HTTP toolkit Hetty, built by David Stotijn as a free alternative to Burp Suite Professional, offers MITM proxy, request interception, and editing capabilities with a single Go binary install, no cost or telemetry.
An autonomous AI agent from depthfirst discovered 21 zero-day vulnerabilities in FFmpeg, including a network-reachable RCE via a single 183-byte packet, for only $1,000 in compute costs; the find highlights the disparity between automated bug finding and patching.
The article proposes a new severity model for vulnerability reporting based on collision counts and the presence of working exploits, arguing that the current disclosure model is broken and that patches should be prioritized when multiple researchers find the same bug or exploits are public.
Calif researchers, with help from the AI tool Mythos Preview, built the first public macOS kernel memory corruption exploit on Apple M5 hardware, bypassing MIE. The exploit chain took 5 days and will be fully disclosed after Apple fixes the vulnerabilities.
Joanna Rutkowska announces the relaunch of her blog after a seven-year hiatus, reflecting on her past work with Qubes OS and her evolving perspective on rationality versus humanism.