vulnerability-research

Tag

Cards List
#vulnerability-research

FreeBSoD: Leveraging Language Models to Find and Exploit Kernel Bugs (Part 2 of 2)

Lobsters Hottest · 2026-07-13 Cached

This article explores using large language models to assist in writing exploits for FreeBSD kernel vulnerabilities, detailing two exploit chains that achieve full jail escape.

0 favorites 0 likes
#vulnerability-research

FreeBSoD: Leveraging Language Models to Find and Exploit Kernel Bugs (Part 1 of 2)

Lobsters Hottest · 2026-07-13 Cached

This article describes how researchers at Praetorian used Claude Opus (via Claude Code) to discover and exploit vulnerabilities in the FreeBSD kernel, including a stack overflow (CVE-2026-3038) that allows escape from FreeBSD jails. Part one focuses on methodology for finding bugs.

0 favorites 0 likes
#vulnerability-research

Hacking Apple - SQL Injection to Remote Code Execution — ProjectDiscovery Blog

Lobsters Hottest · 2026-07-12 Cached

A detailed write-up from ProjectDiscovery detailing how they discovered a critical SQL injection vulnerability in Apple's Book Travel portal via Masa/Mura CMS and achieved Remote Code Execution.

0 favorites 0 likes
#vulnerability-research

Protocol Prying: Vulnerability Research in AirDrop and Quick Share

Hacker News Top · 2026-07-04 Cached

This paper presents the first cross-platform reverse engineering and protocol-aware fuzzing study of Apple AirDrop and Android Quick Share, uncovering six vulnerabilities in these widely used proximity transfer protocols.

0 favorites 0 likes
#vulnerability-research

@hetmehtaa: Local AI for Penetration Testing & Research https://projectblack.io/blog/local-ai-for-cyber-security/…

X AI KOLs Timeline · 2026-07-02 Cached

A blog post benchmarks four approaches (Semgrep, GLM 5.1 with Strix, cloud SOTA with code review skill, and local AI with a custom harness) for finding a known LFI vulnerability in PHPIPAM, finding that the local AI harness with a tailored approach outperforms the others.

0 favorites 0 likes
#vulnerability-research

@OpenAI: GPT-5.6 Sol is our most capable model yet for cybersecurity. It shifts the performance-efficiency frontier for long-hor…

X AI KOLs · 2026-06-26 Cached

OpenAI announces GPT-5.6 Sol, a model specialized for cybersecurity, improving performance-efficiency on long-horizon security tasks like vulnerability research and exploitation.

0 favorites 0 likes
#vulnerability-research

@0x0SojalSec: AI Ghidra and Radare2 : AI-powered reverse engineering. AI agents that can disassemble, decompile, scan with YARA, and …

X AI KOLs Timeline · 2026-06-25 Cached

Reversecore MCP is an enterprise-grade AI-powered reverse engineering and security analysis tool that integrates with AI assistants via the Model Context Protocol, offering 50+ tools for static/dynamic analysis, malware analysis, vulnerability research, and more.

0 favorites 0 likes
#vulnerability-research

Anthropic study shows AI can build working exploits from security patches in hours, not weeks

Reddit r/ArtificialInteligence · 2026-06-11

Anthropic's study demonstrates that large language models can rapidly generate working exploits from security patches, reducing the time from weeks to hours, raising concerns about AI-driven vulnerability exploitation.

0 favorites 0 likes
#vulnerability-research

I built a vulnerable app and spent $1,500 seeing if LLMs could hack it

Hacker News Top · 2026-06-04 Cached

The author built a vulnerable React Native app to test if LLMs could exploit a common Firebase misconfiguration, finding that only a few models (GPT 5.5, Deepseek V4 Pro, Claude Sonnet 4.6, Claude Opus 4-8) succeeded, with GPT 5.5 having the highest solve rate.

0 favorites 0 likes
#vulnerability-research

An AI audit of FreeBSD

Lobsters Hottest · 2026-05-29 Cached

An AI-assisted security audit of FreeBSD uncovered 15 kernel vulnerabilities, including privilege escalations and a VM escape, and details the collaborative process of reporting and patching bugs with the FreeBSD team.

0 favorites 0 likes
#vulnerability-research

Voice AI Systems Are Vulnerable to Hidden Audio Attacks

Hacker News Top · 2026-05-18 Cached

New research shows that imperceptible audio signals can hijack large audio-language models (LALMs) with 79-96% success, forcing them to execute unauthorized commands like web searches or sending emails. The technique, dubbed AudioHijack, targets generative models and works regardless of user input, posing a serious security risk to voice AI systems.

0 favorites 0 likes
#vulnerability-research

Jun 8, 2026Frontier Red TeamMeasuring LLMs’ impact on N-day exploits

Anthropic Research · 2026-06-17 Cached

Anthropic's Frontier Red Team evaluates how large language models can accelerate the exploitation of N-day vulnerabilities, finding that Claude Mythos Preview can autonomously build working exploits for 8 out of 18 Firefox patches and 8 out of 21 Windows kernel patches, highlighting increased threats during the patch gap.

0 favorites 0 likes
← Back to home

Submit Feedback