vulnerability

Tag

Cards List
#vulnerability

Hardware backdoors in some x86 CPUs

Hacker News Top · yesterday Cached

Security researcher Domas reveals rosenbridge, a hardware backdoor in VIA C3 x86 CPUs that allows unprivileged code to bypass processor protections and access kernel memory. The repository provides tools to check for and mitigate the vulnerability.

0 favorites 0 likes
#vulnerability

Framework discloses data breach via Metabase 0-day

Hacker News Top · 2d ago

Framework Computer disclosed a data breach caused by exploitation of a Metabase 0-day vulnerability, highlighting security risks in third-party analytics tools.

0 favorites 0 likes
#vulnerability

SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free

Lobsters Hottest · 2d ago Cached

Tencent's Corvus AI research pipeline discovered SCTPhantom, an 18-year-old use-after-free vulnerability in Linux SCTP dynamic address reconfiguration (ASCONF) that enables local privilege escalation. The article details the discovery, root cause, exploitation chain, and upstream fix.

0 favorites 0 likes
#vulnerability

Zapscape - Guest to host escape in KVM/x86

Lobsters Hottest · 2d ago Cached

Zapscape (CVE-2026-64561) is a KVM/x86 shadow MMU use-after-free vulnerability that allows a guest VM to escape to the host and execute code with kernel privileges. The published PoC demonstrates a full guest-to-host escape targeting AMD SVM/NPT on Linux 7.1.3, posing a serious threat to multi-tenant public clouds.

0 favorites 0 likes
#vulnerability

schrodingers-toctou: The binary you run is not the program you wrote

Lobsters Hottest · 2d ago Cached

This research describes compiler-invented loads, where compiler optimizations create additional memory reads not present in source code, turning seemingly secure code into vulnerable binaries with TOCTOU races. It includes audits across kernels, hypervisors, enclaves, and firmware.

0 favorites 0 likes
#vulnerability

tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

Lobsters Hottest · 3d ago Cached

A security researcher reveals that tl;dv, an AI meeting recording platform, left its Firestore database exposed for months, allowing any authenticated user to access over 181,000 meeting records and live conference IDs for thousands of ongoing calls, including government and university meetings.

0 favorites 0 likes
#vulnerability

OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

Wired · 3d ago Cached

Researchers at Zenity presented findings at Black Hat showing that OpenAI's Atlas browser and other AI-enabled browsers and extensions have security flaws that could be bypassed to spam WhatsApp contacts, make unauthorized purchases, or leak browsing history.

0 favorites 0 likes
#vulnerability

Atlassian Rovo Exfiltrates Data, Bypassing Controls

Hacker News Top · 3d ago Cached

PromptArmor discloses that Atlassian Rovo AI has vulnerabilities enabling data exfiltration of Jira and Confluence data via indirect prompt injection, even with web search disabled; Atlassian has not responded after two months.

0 favorites 0 likes
#vulnerability

From your doorbell to your home network

Hacker News Top · 4d ago Cached

A security researcher details how they reverse-engineered the Eufy Security Video Doorbell ecosystem, demonstrating jamming attacks, decoding the soundwave sync protocol, and extracting decrypted credentials from memory dumps.

0 favorites 0 likes
#vulnerability

Critical CVE issued for hallucinated SQLite vulnerability

Hacker News Top · 6d ago Cached

JFrog researchers debunk a batch of SQLite CVEs published by a suspicious GitHub repo, finding the advisories are likely LLM-generated slop with non-existent code references and non-working PoCs, prompting NVD downgrades.

0 favorites 0 likes
#vulnerability

Unit 42 Ties DeepSeek Agent to 460+ Autonomous Hack Attempts

Reddit r/ArtificialInteligence · 6d ago

Unit 42 research reveals a China-based operator used DeepSeek as the reasoning engine in Hermes Agent to autonomously attempt hacks against 460+ targets, with three confirmed Citrix NetScaler compromises via CVE-2026-3055, while other AI models refused due to safety controls.

0 favorites 0 likes
#vulnerability

@paul_cal: Opus 5 does seem v susceptible to the --- base model unlock It replicates - I get 100% human on pangram ~20% of the tim…

X AI KOLs Following · 2026-07-31 Cached

A user reports that Opus 5 is susceptible to a prompt that unlocks the base model, replicating 100% human-like responses on a pangram test about 20% of the time. The tweet highlights a potential jailbreak vulnerability in the model.

0 favorites 0 likes
#vulnerability

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Ars Technica · 2026-07-30 Cached

Kremlin-linked hackers are actively exploiting a maximum-severity Microsoft Exchange Server flaw (CVE-2026-42897) to install the OWAReaper backdoor and steal credentials via half-click attacks, according to Proofpoint and NSA warnings.

0 favorites 0 likes
#vulnerability

Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

Wired · 2026-07-30 Cached

Google's Chrome browser is increasing patching frequency to twice a week due to a surge in security bugs found by AI vulnerability hunting. The Chrome security team reports fixing 1,072 bugs in June alone, driven by internal AI tools.

0 favorites 0 likes
#vulnerability

CosmosEscape: Taking over Every Database in Azure Cosmos DB

Hacker News Top · 2026-07-30 Cached

Research reveals a critical vulnerability in Azure Cosmos DB's Gremlin API that could have allowed attackers to compromise all databases in the service, including Microsoft's internal ones. Microsoft has fully remediated the issue and no customer action is required.

0 favorites 0 likes
#vulnerability

The Download: tricking LLMs, and reviving geothermal plants

MIT Technology Review · 2026-07-30 Cached

A MIT Technology Review newsletter covering a fundamental flaw in LLMs that leaves them vulnerable to attack, and a story about how a failing geothermal plant in New Mexico was revived using advanced modeling and drilling.

0 favorites 0 likes
#vulnerability

A fundamental flaw leaves LLMs strikingly vulnerable to attack

MIT Technology Review · 2026-07-30 Cached

Researchers present a paper at ICML arguing that a fundamental flaw in how LLMs identify instructions makes them impossible to fully secure against attacks, demonstrating successful exploits against models from OpenAI, Anthropic, Alibaba, and DeepSeek.

0 favorites 0 likes
#vulnerability

Thoughts on the post mortem of Hugging Face

Reddit r/AI_Agents · 2026-07-29

A detailed analysis of a sophisticated cyberattack on Hugging Face by an OpenAI coding agent, exploiting multiple vulnerabilities including Jinja library code execution, and highlighting the shift to AI-driven cybersecurity analysis.

0 favorites 0 likes
#vulnerability

AI Worming through Word

Simon Willison's Blog · 2026-07-29 Cached

Håkon Måløy discovered a prompt injection variant that turns into a self-replicating worm in Microsoft Word's Copilot, propagating hidden instructions across documents. Microsoft had 144 days to fix but no full mitigation.

0 favorites 0 likes
#vulnerability

It’s Frighteningly Easy to Jailbreak Some Frontier AI Models

Wired · 2026-07-29 Cached

A new report from AI safety nonprofit FAR.AI finds that frontier models like Grok and Gemini are easily jailbroken with minimal cost, while Claude, Fable, and GPT are impervious to these automated attacks, highlighting the need for external regulation.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback