Tag
OpenClaw completed a security audit through OpenAI’s Patch the Planet initiative, identifying and fixing 24 severity-rated vulnerabilities with the help of Trail of Bits using Codex-assisted workflows.
Hackers breached OpenAI by exploiting vulnerabilities in third-party systems and employee validation, raising security and safety concerns in AI development. The researchers were white-hat and reported the issue, which has been patched.
Researchers from Hacktron AI used Anthropic's Claude to exploit vulnerabilities in OpenAI's systems, demonstrating AI's capability in cybersecurity and raising concerns about AI security vulnerabilities.
Security researchers discovered and disclosed vulnerabilities that allowed them to compromise OpenAI employees' accounts and access internal repositories through an exploit chain involving libheif and an SSO misconfiguration.
Independent security researchers discovered a critical vulnerability chain involving an SSO misconfiguration and image decoder flaw in OpenAI's systems, using Anthropic's Claude to gain access to internal repositories and triggering a security patch.
The article highlights the lack of robust security practices in agentic AI deployments, pointing out that many projects fail to apply standard security measures like logging and least privilege, and references OWASP's Top 10 and the AIUC-1 standard.
Anthropic's report describes a case where two undergraduates used Claude to automate a 24-hour cyber attack system, generating 0-day vulnerabilities and running AI agents for continuous intelligence collection, illustrating how AI amplifies capabilities for individuals and small teams.
An exploit kit named BlueMoon, targeting critical vulnerabilities in Chromium browsers and Windows, has been used by at least four hacking groups, some with ties to the Chinese government. Researchers from Proofpoint reported rapid deployment and sharing of the kit, possibly aided by AI, within a patch gap in the Chromium supply chain.
Security researchers discovered that LG smart TVs log plaintext transcripts and map network devices even when off, revealing invasive surveillance practices and potential vulnerabilities in over 200 million devices worldwide.
Microsoft patched a record 972 vulnerabilities in September 2026, with 112 critical, amid industry warnings about AI-enabled cyber attacks.
A practical walkthrough on how to test AI agents with multi-turn attacks to uncover vulnerabilities that seem harmless in isolation but become critical over interactions.
A tweet discusses how AI models are becoming highly effective at identifying and exploiting cybersecurity vulnerabilities, and references OpenAI's preview of Astra as a major advancement in AI cybersecurity capability.
The article discusses how a surge in cybersecurity vulnerabilities, referred to as 'Vulnpocalypse,' is leading to reevaluation and changes in the pricing structures of bug bounty programs.
OpenAI's forthcoming Astra model is designed to excel in cybersecurity by identifying and exploiting zero-day vulnerabilities, prompting the company to implement strict safety measures before its public release.
OpenAI announced the upcoming release of its Astra model, which is the first to achieve 'critical' cyber capabilities, allowing it to find and exploit software vulnerabilities. The company plans a public release soon, with advanced features limited to select partners for safety reasons.
Security researcher Matt Burch disclosed nine vulnerabilities in CryptoPro Secure Disk software that could bypass encryption, revealing critical weaknesses in the software supply chain affecting ATMs and other industries.
The article highlights the significant role of AI models like Mythos in cybersecurity, revealing a surge in critical vulnerabilities at Oracle and detailing AI-driven discovery efforts by Anthropic and OpenAI.
An AI agent autonomously scans major open-source repositories, writes patches for security vulnerabilities, and opens pull requests that human maintainers review and merge, with its success measured by merged fixes.
Researchers disclosed vulnerabilities in Zoom's screen-sharing annotation protocol that could allow silent device takeover; the flaws were discovered using AI models in under 20 prompts, with fixes already rolling out.
Microsoft released patches for nearly 400 security vulnerabilities, including one actively exploited zero-day, as AI-driven discovery continues to swell patch volumes.