vulnerability-disclosure

Tag

Cards List
#vulnerability-disclosure

AI Meets Cryptography 1: What AI Found in Cloudflare's Circl

Hacker News Top · 2026-07-07 Cached

Using AI audit agents, zkSecurity discovered seven real bugs in Cloudflare's CIRCL cryptography library, including critical precision loss and access-control break. All bugs have been fixed upstream.

0 favorites 0 likes
#vulnerability-disclosure

Exploiting vulnerabilities in Johnson and Johnson web apps

Hacker News Top · 2026-06-24 Cached

Security researcher Eaton discloses vulnerabilities in Johnson & Johnson's Campus Recruiting and Audit Tracking Management System web apps, exposing student data and allowing admin takeover due to flawed authentication using hardcoded API keys.

0 favorites 0 likes
#vulnerability-disclosure

Microsoft is threatening legal action for disclosing exploits

The Verge · 2026-05-30 Cached

Microsoft is facing backlash for threatening legal action against a security researcher who publicly posted zero-day exploits, with critics highlighting the company's inconsistent history with vulnerability disclosure.

0 favorites 0 likes
#vulnerability-disclosure

Microsoft Threatened Legal Action Against a Security Researcher. The Security Community Pushed Back.

Reddit r/ArtificialInteligence · 2026-05-29 Cached

A security researcher published six unpatched Windows zero-day vulnerabilities, including working exploit code, without Microsoft's knowledge. Microsoft threatened legal action and criminal referrals, drawing widespread criticism from the cybersecurity community over its handling of the situation.

0 favorites 0 likes
#vulnerability-disclosure

Microsoft 0-day feud escalates as researcher threatens another exploit dump

Hacker News Top · 2026-05-29 Cached

A disgruntled security researcher known as Nightmare Eclipse has escalated a feud with Microsoft by threatening to dump more Windows zero-day exploits, after already releasing six. Microsoft has responded with a blog post and legal threats.

0 favorites 0 likes
#vulnerability-disclosure

The AI Era Is Creating a Bug Hunting Arms Race

Wired · 2026-05-25 Cached

The article explores how AI-powered bug hunting is flooding vulnerability disclosure programs, changing the economics of bug bounties, and compressing disclosure timelines, while also benefiting attackers.

0 favorites 0 likes
#vulnerability-disclosure

score by collisions, patch by panic

Lobsters Hottest · 2026-05-22 Cached

The article proposes a new severity model for vulnerability reporting based on collision counts and the presence of working exploits, arguing that the current disclosure model is broken and that patches should be prioritized when multiple researchers find the same bug or exploits are public.

0 favorites 0 likes
#vulnerability-disclosure

They will force you, open source maintainers, to drink the gasoline (adopting AI)

Lobsters Hottest · 2026-04-22 Cached

Security researchers warn that an oncoming flood of AI-generated vulnerability reports will overwhelm open-source maintainers, forcing projects to adopt AI triage tools or risk drowning in low-quality submissions.

0 favorites 0 likes
#vulnerability-disclosure

Outbound coordinated vulnerability disclosure policy

OpenAI Blog · 2025-09-22 Cached

OpenAI has published its outbound coordinated vulnerability disclosure policy, outlining how it responsibly reports security vulnerabilities discovered in third-party software to vendors and open-source maintainers, including through AI-powered security analysis. The policy covers detection methods, peer review processes, and disclosure procedures under its Security Research team branded 'Aardvark'.

0 favorites 0 likes
#vulnerability-disclosure

Working with US CAISI and UK AISI to build more secure AI systems

OpenAI Blog · 2025-09-12 Cached

OpenAI announces collaborative security improvements with US CAISI and UK AISI, highlighting joint red-teaming efforts that discovered and helped remediate novel vulnerabilities in ChatGPT Agent systems through multidisciplinary cybersecurity and AI agent security approaches.

0 favorites 0 likes
#vulnerability-disclosure

Scaling security with responsible disclosure

OpenAI Blog · 2025-06-09 Cached

OpenAI publishes an Outbound Coordinated Vulnerability Disclosure Policy outlining how it responsibly reports security vulnerabilities discovered in third-party software, anticipating increased vulnerability detection as AI systems become more capable at finding and patching security issues.

0 favorites 0 likes
← Back to home

Submit Feedback