Tag
Using AI audit agents, zkSecurity discovered seven real bugs in Cloudflare's CIRCL cryptography library, including critical precision loss and access-control break. All bugs have been fixed upstream.
Security researcher Eaton discloses vulnerabilities in Johnson & Johnson's Campus Recruiting and Audit Tracking Management System web apps, exposing student data and allowing admin takeover due to flawed authentication using hardcoded API keys.
Microsoft is facing backlash for threatening legal action against a security researcher who publicly posted zero-day exploits, with critics highlighting the company's inconsistent history with vulnerability disclosure.
A security researcher published six unpatched Windows zero-day vulnerabilities, including working exploit code, without Microsoft's knowledge. Microsoft threatened legal action and criminal referrals, drawing widespread criticism from the cybersecurity community over its handling of the situation.
A disgruntled security researcher known as Nightmare Eclipse has escalated a feud with Microsoft by threatening to dump more Windows zero-day exploits, after already releasing six. Microsoft has responded with a blog post and legal threats.
The article explores how AI-powered bug hunting is flooding vulnerability disclosure programs, changing the economics of bug bounties, and compressing disclosure timelines, while also benefiting attackers.
The article proposes a new severity model for vulnerability reporting based on collision counts and the presence of working exploits, arguing that the current disclosure model is broken and that patches should be prioritized when multiple researchers find the same bug or exploits are public.
Security researchers warn that an oncoming flood of AI-generated vulnerability reports will overwhelm open-source maintainers, forcing projects to adopt AI triage tools or risk drowning in low-quality submissions.
OpenAI has published its outbound coordinated vulnerability disclosure policy, outlining how it responsibly reports security vulnerabilities discovered in third-party software to vendors and open-source maintainers, including through AI-powered security analysis. The policy covers detection methods, peer review processes, and disclosure procedures under its Security Research team branded 'Aardvark'.
OpenAI announces collaborative security improvements with US CAISI and UK AISI, highlighting joint red-teaming efforts that discovered and helped remediate novel vulnerabilities in ChatGPT Agent systems through multidisciplinary cybersecurity and AI agent security approaches.
OpenAI publishes an Outbound Coordinated Vulnerability Disclosure Policy outlining how it responsibly reports security vulnerabilities discovered in third-party software, anticipating increased vulnerability detection as AI systems become more capable at finding and patching security issues.