security-research
146 articles with this tag
INFO
INFO
MEDIUM
INFO
INFO
INFO
HIGH
MEDIUM
HIGH
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
HIGH
INFO
INFO
INFO
CRITICAL
MEDIUM
INFO
MEDIUM
MEDIUM
INFO
INFO
MEDIUM
INFO
INFO
INFO
INFO
INFO
INFO
HIGH
MEDIUM
MEDIUM
INFO
INFO
INFO
MEDIUM
INFO
INFO
MEDIUM
INFO
MEDIUM
MEDIUM
INFO
INFO
INFO
INFO
INFO
INFO
MEDIUM
INFO
MEDIUM
CRITICAL
MEDIUM
INFO
INFO
INFO
HIGH
INFO
INFO
INFO
HIGH
INFO
CRITICAL
INFO
INFO
MEDIUM
MEDIUM
MEDIUM
HIGH
LOW
INFO
MEDIUM
INFO
INFO
INFO
MEDIUM
HIGH
INFO
CRITICAL
INFO
HIGH
INFO
INFO
INFO
LOW
INFO
MEDIUM
INFO
INFO
HIGH
HIGH
Phishing Research Challenges Conventional Security Awareness Testing
Autonomous Systems Emissions Index
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026)
A security framework for coding agents and their harnesses
The state of AI for security: Measuring what matters most for building trust
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
Google Researchers Hacked the Pixel Phone using Audio Messages
Phishing Panel Breadcrumbs
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
The Curious Incidents with DNS in the Sandbox at Escape-Time
Finding Hidden Internal Apps Through Public Certificate Logs
10 Hacker Summer Camp Standouts at Black Hat and DEF CON
Dissecting House of Apple 2 on modern glibc
AI can find zero-days but still can’t reliably write secure code
Finding Hidden Internal Apps Through Public Certificate Logs
Putting OpenAI Cyber Models to Work for Defenders
The AI harness is the new attack surface
Post-quantum migration gets harder when every user holds a key
Can AI Build Hacker Traps That Actually Work?
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
The future of AI security research isn’t autonomous, it’s human-amplified
Black Hat: AI isn't the problem. We are
BTS #79 - InfraTrust - Understanding Infrastructure Vulnerabilities & Risk
Human oversight is still critical as AI patching tools miss security risks
Island's Michael Leland on the hidden risks of the AI supply chain
Black Hat 2026: Open-source tool makes red teaming AI agents up to 125x cheaper
Researchers find ‘agent-to-agent’ privilege escalation in Google’s ADK for Python repo
Before the first prompt: Code execution paths in trusted coding-agent projects
Why Your SOC Needs an Open-Weight AI Model | BHIS In Focus
Red Agents vs. Blue Agents: How to Make AI Better At Defense
Android malware detection collapses when the context stage comes out
Pollard's P-1 Factoring Algorithm in Plain C
How Synthetic Identity Fraud is Coming for Machine Identities
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
An AI overthinking attack can tie a robot up for over a minute
Fake smart home residents could stand in for real ones in security research
AI Found a Root Bug in Linux That Everyone Missed for 15 Years
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
Proxy Execution with Microsoft Edge WebView2 - Matthew Eidelberg
OpenAI and Anthropic are pulling in different directions
"Exploit mitigation" stalled around 2008. The attacks didn't.
What the AI patch gap means for enterprise security
Reverse Engineering EDRs | BHIS - Talkin' Bout [infosec] News
NIST Enrichment Reductions Impact CVE Coverage, Accuracy
A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain
Mozilla warns of indirect prompt injection risk in AI coding agents
Applying DI in C to decouple Windows exploitation from the execution mechanics
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026)
CargoWise WebTracker - The keys were in the cargo
Interesting Paper Exploring Prompt Injection
Beyond the benchmark: Advancing security at AI speed
Encrypted DNS still tells an eavesdropper where to look
Defending bot-detection code that runs on the attacker's own machine
Beyond the benchmark: Advancing security at AI speed
Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker
Researcher accidentally gained access to a threat actor-controlled phishing website
XBOW tests Anthropic's Mythos Preview for offensive security
AI Agents May Always Fall for Prompt Injections
Security Researchers Are Threat Actors - PSW #929
Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook
Smashing Security podcast #470: This AI security flaw might be impossible to fix
Anthropic Expands Mythos Access to 150 More Organizations
Microsoft reaches for olive branch after public dustup with 0-day researcher
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
Visual Studio Extensions Revisited
DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap
Continuous Offensive Security: The Line We've Been Walking
Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects
OpenHack: Open-source AI-powered vulnerability research
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Cisco used AI to write security incident reports, with mixed results
AI red teaming agents change how LLMs get tested
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
New image-based prompt injection attack targets multimodal AI models
Security Researchers Find 47 Zero-Days at Pwn2Own Berlin
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
Zombie linkages are keeping expired domains trusted for years
On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract
Memory Poisoning AI Agents via ChromaDB
What Mozilla learned running an AI security bug hunting pipeline on Firefox
One keypress is all it takes to compromise four AI coding tools
Attackers Could Exploit AI Vision Models Using Imperceptible Image Changes
Proof of Selective Triage: Deribit resolving other H1 reports while ghosting Critical researcher for 76+ days
Nine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security Researcher
Automated LLM red teaming gets a learning layer
We’re in a Patch Apocalypse. That Means These Three IT Excuses Won’t Work Anymore.
Extending Ruzzy with LibAFL
Claude Mythos Has Found 271 Zero-Days in Firefox
Attempting to evade an AI SOC with offensive agents
It's a myth that you need Mythos to find bugs: Open source models can do it just as well
Mythos Special: A Big Bug Problem with Gadi Evron, Rob Lee and Ed Skoudis
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026)
Chinese Cybersecurity Firm’s AI Hacking Claims Draw Comparisons to Claude Mythos
Claude Mythos signals a new era in AI-driven security, finding 271 flaws in Firefox
Anthropic bets on EPSS for the coming bug surge
Meta and PortSwigger drive offensive security further to find what others miss
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 6, 2026 to April 12, 2026)
Wordfence Intelligence Weekly WordPress Vulnerability Report (March 30, 2026 to April 5, 2026)