vulnerability-research

Tag

Cards List
#vulnerability-research

How AI guardrails are impeding the work of offensive cybersecurity researchers

TechCrunch AI · 12h ago Cached

AI safety guardrails intended to prevent malicious use are also hindering legitimate offensive cybersecurity researchers, who need unrestricted model access to identify and exploit vulnerabilities for defense. Researchers criticize the arbitrary gatekeeping by AI companies like Anthropic and OpenAI.

0 favorites 0 likes
#vulnerability-research

FreeBSoD: Leveraging Language Models to Find and Exploit Kernel Bugs (Part 2 of 2)

Lobsters Hottest · 2026-07-13 Cached

This article explores using large language models to assist in writing exploits for FreeBSD kernel vulnerabilities, detailing two exploit chains that achieve full jail escape.

0 favorites 0 likes
#vulnerability-research

FreeBSoD: Leveraging Language Models to Find and Exploit Kernel Bugs (Part 1 of 2)

Lobsters Hottest · 2026-07-13 Cached

This article describes how researchers at Praetorian used Claude Opus (via Claude Code) to discover and exploit vulnerabilities in the FreeBSD kernel, including a stack overflow (CVE-2026-3038) that allows escape from FreeBSD jails. Part one focuses on methodology for finding bugs.

0 favorites 0 likes
#vulnerability-research

Hacking Apple - SQL Injection to Remote Code Execution — ProjectDiscovery Blog

Lobsters Hottest · 2026-07-12 Cached

A detailed write-up from ProjectDiscovery detailing how they discovered a critical SQL injection vulnerability in Apple's Book Travel portal via Masa/Mura CMS and achieved Remote Code Execution.

0 favorites 0 likes
#vulnerability-research

Protocol Prying: Vulnerability Research in AirDrop and Quick Share

Hacker News Top · 2026-07-04 Cached

This paper presents the first cross-platform reverse engineering and protocol-aware fuzzing study of Apple AirDrop and Android Quick Share, uncovering six vulnerabilities in these widely used proximity transfer protocols.

0 favorites 0 likes
#vulnerability-research

@hetmehtaa: Local AI for Penetration Testing & Research https://projectblack.io/blog/local-ai-for-cyber-security/…

X AI KOLs Timeline · 2026-07-02 Cached

A blog post benchmarks four approaches (Semgrep, GLM 5.1 with Strix, cloud SOTA with code review skill, and local AI with a custom harness) for finding a known LFI vulnerability in PHPIPAM, finding that the local AI harness with a tailored approach outperforms the others.

0 favorites 0 likes
#vulnerability-research

@OpenAI: GPT-5.6 Sol is our most capable model yet for cybersecurity. It shifts the performance-efficiency frontier for long-hor…

X AI KOLs · 2026-06-26 Cached

OpenAI announces GPT-5.6 Sol, a model specialized for cybersecurity, improving performance-efficiency on long-horizon security tasks like vulnerability research and exploitation.

0 favorites 0 likes
#vulnerability-research

@0x0SojalSec: AI Ghidra and Radare2 : AI-powered reverse engineering. AI agents that can disassemble, decompile, scan with YARA, and …

X AI KOLs Timeline · 2026-06-25 Cached

Reversecore MCP is an enterprise-grade AI-powered reverse engineering and security analysis tool that integrates with AI assistants via the Model Context Protocol, offering 50+ tools for static/dynamic analysis, malware analysis, vulnerability research, and more.

0 favorites 0 likes
#vulnerability-research

Anthropic study shows AI can build working exploits from security patches in hours, not weeks

Reddit r/ArtificialInteligence · 2026-06-11

Anthropic's study demonstrates that large language models can rapidly generate working exploits from security patches, reducing the time from weeks to hours, raising concerns about AI-driven vulnerability exploitation.

0 favorites 0 likes
#vulnerability-research

I built a vulnerable app and spent $1,500 seeing if LLMs could hack it

Hacker News Top · 2026-06-04 Cached

The author built a vulnerable React Native app to test if LLMs could exploit a common Firebase misconfiguration, finding that only a few models (GPT 5.5, Deepseek V4 Pro, Claude Sonnet 4.6, Claude Opus 4-8) succeeded, with GPT 5.5 having the highest solve rate.

0 favorites 0 likes
#vulnerability-research

An AI audit of FreeBSD

Lobsters Hottest · 2026-05-29 Cached

An AI-assisted security audit of FreeBSD uncovered 15 kernel vulnerabilities, including privilege escalations and a VM escape, and details the collaborative process of reporting and patching bugs with the FreeBSD team.

0 favorites 0 likes
#vulnerability-research

Voice AI Systems Are Vulnerable to Hidden Audio Attacks

Hacker News Top · 2026-05-18 Cached

New research shows that imperceptible audio signals can hijack large audio-language models (LALMs) with 79-96% success, forcing them to execute unauthorized commands like web searches or sending emails. The technique, dubbed AudioHijack, targets generative models and works regardless of user input, posing a serious security risk to voice AI systems.

0 favorites 0 likes
#vulnerability-research

Jun 8, 2026Frontier Red TeamMeasuring LLMs’ impact on N-day exploits

Anthropic Research · 2026-06-17 Cached

Anthropic's Frontier Red Team evaluates how large language models can accelerate the exploitation of N-day vulnerabilities, finding that Claude Mythos Preview can autonomously build working exploits for 8 out of 18 Firefox patches and 8 out of 21 Windows kernel patches, highlighting increased threats during the patch gap.

0 favorites 0 likes
← Back to home

Submit Feedback