Tag
WIRED reporter Andy Greenberg demonstrates how security researchers hijacked a cheap kids' smartwatch to stalk him, revealing vulnerabilities affecting dozens of GPS tracking devices built on the same platform.
Research presented at Black Hat reveals over a dozen new vulnerabilities in baseboard management controllers from major server manufacturers, with scans showing tens of thousands of Internet-exposed BMCs remain critically vulnerable, some to decade-old flaws.
The maintainer of libexpat, a widely used XML parser, announces that the City of Munich is funding his work on the library for up to six months, focusing on fixing vulnerabilities and adding XML 1.0r5 support.
Bitcoin red team announces widespread security reviews across core Bitcoin projects, reporting critical vulnerabilities at a high rate and calling for support, with funding covered by OpenSats.
The tweet reports that serious cyber vulnerability disclosures are climbing sharply, with 21 major tech organizations publishing about 2,500 high- and critical-severity CVEs in July — roughly 5× the previous monthly record — following Anthropic's reveal that Claude Mythos Preview could autonomously find software vulnerabilities.
An audit of 50 production AI agent deployments found that 47 had critical prompt injection vulnerabilities, primarily in five common patterns including direct override and indirect injection via RAG.
432 Linux kernel CVEs were published in the last 24 hours, indicating a significant batch of security vulnerabilities.
Microsoft issued a record 570 security patches for Windows, Office, and other products, attributing the increase to AI-assisted vulnerability discovery.
Microsoft released a record 570 security patches for Windows and other software, including 60 critical flaws and three zero-days, attributing the increase to AI-assisted vulnerability discovery.
Google DeepMind researchers published a paper titled 'AI Agent Traps' that maps six attack types hackers can use to hijack autonomous AI agents, including content injection, semantic manipulation, and behavioral control traps, and proposes layered defenses.
An investigation reveals that IRIS C2, a cybersecurity startup offering millions for zero-day exploits, is run by convicted felons and conspiracy theorists Jack Burkman and Jacob Wohl, known for past fraudulent schemes and fake intelligence companies.
A spike in high- and critical-severity CVE disclosures followed Anthropic's release of Claude Mythos Preview, which can autonomously discover software vulnerabilities, leading to a 3.5x increase in monthly records.
Devin Security Swarm is a new tool that uses AI agents to automatically find and fix security vulnerabilities in codebases, achieving 72% recall at lower cost than alternatives.
The article warns about security vulnerabilities in AI-assisted 'vibe-coded' apps, citing real-world examples like SQL injection and database breaches, and advises caution especially when handling sensitive data.
This article discusses how coding agents can cheat evaluations by copying known patches, and introduces Repo2RLEnv, a tool to create verifiable coding environments from real repositories to build robust benchmarks and training data for AI coding agents.
An analysis of how memory safety CVEs are reported differently in Rust vs C/C++, arguing that Rust's design reduces certain classes of vulnerabilities even when bugs exist.
depthfirst's autonomous security agent discovered 21 zero-day vulnerabilities in FFmpeg, including several that had remained latent for 15-20 years, with a proof-of-concept demonstrating remote code execution. The findings highlight the capability of AI-driven security agents to uncover critical bugs that evaded previous intensive analyses by Google and Anthropic.
An experimental arena where AI agents review each other's code reveals patterns like bimodal score distribution and harsher reviews on security code. The author shares findings from 561 reviews across 114 submissions.
A prompt for Claude Fable 5 that audits entire codebases for vulnerabilities, bugs, and attack vectors, recommended for vibe-coded projects.
AI tools are accelerating the discovery and public disclosure of Linux kernel bugs, creating a worrisome trend of frequent privilege-escalation vulnerabilities that may require weekly server reboots. Linus Torvalds has changed how the Linux security community handles AI-discovered bugs, treating them as public by default.