security-research
131 articles with this tag
INFO
INFO
INFO
INFO
INFO
INFO
INFO
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
INFO
INFO
MEDIUM
INFO
INFO
MEDIUM
INFO
INFO
MEDIUM
INFO
MEDIUM
MEDIUM
INFO
INFO
MEDIUM
INFO
INFO
MEDIUM
INFO
MEDIUM
INFO
INFO
INFO
INFO
INFO
MEDIUM
INFO
MEDIUM
CRITICAL
MEDIUM
INFO
INFO
INFO
MEDIUM
INFO
INFO
INFO
INFO
INFO
HIGH
INFO
CRITICAL
INFO
INFO
MEDIUM
INFO
MEDIUM
MEDIUM
HIGH
LOW
INFO
MEDIUM
INFO
INFO
INFO
MEDIUM
HIGH
INFO
CRITICAL
INFO
HIGH
INFO
INFO
INFO
LOW
INFO
MEDIUM
INFO
INFO
HIGH
HIGH
INFO
HIGH
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
CRITICAL
INFO
MEDIUM
HIGH
CRITICAL
Pollard's P-1 Factoring Algorithm in Plain C
Beyond the Model: Harnessing Frontier AI for Stronger Cyber Defense
How Synthetic Identity Fraud is Coming for Machine Identities
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
An AI overthinking attack can tie a robot up for over a minute
Fake smart home residents could stand in for real ones in security research
CrowdStrike Uncovers New Prompt Injection Techniques
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
AI Found a Root Bug in Linux That Everyone Missed for 15 Years
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
Proxy Execution with Microsoft Edge WebView2 - Matthew Eidelberg
OpenAI and Anthropic are pulling in different directions
"Exploit mitigation" stalled around 2008. The attacks didn't.
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment
What the AI patch gap means for enterprise security
Reverse Engineering EDRs | BHIS - Talkin' Bout [infosec] News
NIST Enrichment Reductions Impact CVE Coverage, Accuracy
A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain
Mozilla warns of indirect prompt injection risk in AI coding agents
Applying DI in C to decouple Windows exploitation from the execution mechanics
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026)
CargoWise WebTracker - The keys were in the cargo
Interesting Paper Exploring Prompt Injection
Beyond the benchmark: Advancing security at AI speed
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment
New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment
Encrypted DNS still tells an eavesdropper where to look
Defending bot-detection code that runs on the attacker's own machine
Beyond the benchmark: Advancing security at AI speed
Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker
Researcher accidentally gained access to a threat actor-controlled phishing website
XBOW tests Anthropic's Mythos Preview for offensive security
AI Agents May Always Fall for Prompt Injections
Security Researchers Are Threat Actors - PSW #929
Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook
Smashing Security podcast #470: This AI security flaw might be impossible to fix
Anthropic Expands Mythos Access to 150 More Organizations
Microsoft reaches for olive branch after public dustup with 0-day researcher
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
CrowdStrike Named a Leader in the First-Ever Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies
Visual Studio Extensions Revisited
DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap
CrowdStrike Named a Leader in the First-Ever Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies
Continuous Offensive Security: The Line We've Been Walking
Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects
OpenHack: Open-source AI-powered vulnerability research
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Cisco used AI to write security incident reports, with mixed results
AI red teaming agents change how LLMs get tested
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
Now Live: The CrowdStrike 2026 Financial Services Threat Landscape Report
New image-based prompt injection attack targets multimodal AI models
Security Researchers Find 47 Zero-Days at Pwn2Own Berlin
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
Zombie linkages are keeping expired domains trusted for years
On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract
Memory Poisoning AI Agents via ChromaDB
What Mozilla learned running an AI security bug hunting pipeline on Firefox
One keypress is all it takes to compromise four AI coding tools
Attackers Could Exploit AI Vision Models Using Imperceptible Image Changes
Proof of Selective Triage: Deribit resolving other H1 reports while ghosting Critical researcher for 76+ days
Nine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security Researcher
Automated LLM red teaming gets a learning layer
We’re in a Patch Apocalypse. That Means These Three IT Excuses Won’t Work Anymore.
Extending Ruzzy with LibAFL
Claude Mythos Has Found 271 Zero-Days in Firefox
Attempting to evade an AI SOC with offensive agents
It's a myth that you need Mythos to find bugs: Open source models can do it just as well
Mythos Special: A Big Bug Problem with Gadi Evron, Rob Lee and Ed Skoudis
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026)
Chinese Cybersecurity Firm’s AI Hacking Claims Draw Comparisons to Claude Mythos
Claude Mythos signals a new era in AI-driven security, finding 271 flaws in Firefox
Anthropic bets on EPSS for the coming bug surge
Meta and PortSwigger drive offensive security further to find what others miss
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 6, 2026 to April 12, 2026)
Wordfence Intelligence Weekly WordPress Vulnerability Report (March 30, 2026 to April 5, 2026)
Anonymous credentials: an illustrated primer (Part 2)
Metasploit Wrap-Up 04/17/2026
Sometimes changing the password on your email mailbox isn’t enough
How AI is getting better at finding security holes
The 60ms Window: How Event 5156 Solves the ADWS Attribution Problem
The ADWS Architecture That Hides PowerShell AD Enumeration
Anthropic's Project Glasswing CVE tally is still anyone's guess
OpenAI Unveils GPT-5.4-Cyber for Improving Cyber Defense With AI
UK gov's Mythos AI tests help separate cybersecurity threat from hype
Testing reveals Claude Mythos’s offensive capabilities and limits
Your MTTD Looks Great. Your Post-Alert Gap Doesn't
Fixing vulnerability data quality requires fixing the architecture first
We combined DRAM timing attacks, electrical grid frequency detection, and gyroscope fusion into a single bot detection stack and I think we need to talk about it
Claude + Humans vs nginx: CVE-2026-27654
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About