Anthropic's Frontier Red Team analyzes GLM-5.3, an AI model from Zhipu AI that autonomously builds cyber exploits with capabilities matching Claude Mythos Preview. Unlike safeguarded US models, GLM-5.3 was released publicly without meaningful safeguards, allowing attackers to bypass them 64-100% of the time, significantly increasing malicious cyber capabilities while also benefiting defenders.
GitHub Security Lab created an open source AI security agent to automate vulnerability detection in Android applications, discovering 24 vulnerabilities through custom taskflows that guide AI models to find complex security issues. The taskflows are available for researchers to run on their own projects and have identified high-impact flaws in popular apps like OsmAnd.
OpenSecurityTraining2 is a collection of security training courses covering architecture, debugging, reverse engineering, vulnerability analysis, exploit development, secure development, and other defensive security topics.
Security researcher Gal Weizman demonstrated how malicious browser extensions could hijack AI assistants in Chrome, Edge, and other browsers through the BragJack research. The attack exploited how AI systems separate their decision-making from browser execution, allowing extensions to manipulate network requests and gain unauthorized access to files, screenshots, and device capabilities. The findings earned over $20,000 in bug bounties and prompted vendors including Google to release patches.
Mobile applications frequently neglect API security during testing, risking exposure of sensitive data, authentication mechanisms, and business logic. Comprehensive mobile security assessments must evaluate both the application and its APIs to identify vulnerabilities and improve overall security.
Two flagship LLMs, Claude Opus 5.5 and Kimi K3, were compared in building network worms for Pokémon Emerald by finding novel vulnerabilities and exploits. Both models discovered the same link-cable vulnerability and created game-breaking worms, though they took different approaches, found different bugs, and had varying responses to ethical guardrails around piracy and malware creation.
A developer-focused platform aggregating security advisories, service outages, and releases. Recent critical vulnerabilities include XSS bypasses in SunEditor and OpenBao, local file disclosure in LangChain NVIDIA endpoints, and account takeover risks in Klever-Go. Multiple services like GitHub, Datadog, Netlify, and Supabase experienced ongoing outages.
Computer security faces fundamental problems due to flawed foundational ideas, particularly 'Default Permit' policies that allow all traffic or code execution by default unless explicitly blocked. This approach creates endless arms races with attackers and remains widespread despite decades of evidence that deny-by-default strategies are superior.
A critical security patch was deployed for $LUNC in Q3 2026 to address smart contract vulnerabilities and reduce exploit risk, intended to boost institutional confidence.
A discussion on X about a Bitget custody incident clarifies it was not a smart contract exploit but rather a failure in custody infrastructure and signer access controls. The conversation highlights growing smart contract security concerns, with Cardano announcing a roundtable on AI-driven vulnerabilities and auditing practices.
Researchers discovered decades-old file security vulnerabilities affecting Android, Linux, macOS, and Windows operating systems. The flaws pose widespread risk across multiple platforms used by billions of devices globally.
Submersion AI launched Basin, a specialized cybersecurity AI model that ranks 8th globally on the CyberGym benchmark with an 80.8% score, outperforming larger models like Grok 4.7 and Opus 4.8 while costing a fraction as much. Basin discovered high-severity zero-day vulnerabilities in enterprise software and can be deployed entirely on-premises or air-gapped to protect sensitive data.
Cursor released two AI bots for software development: Rollouts monitors code changes from pull request to production, detects regressions, and can automatically revert problematic changes; Security Reviewer scans code for vulnerabilities and proposes fixes. Both tools automate repetitive post-PR tasks to accelerate safe code deployment.
A web crawler named lawa discovered significant HTTP header inconsistencies across millions of requests, including variable capitalization patterns, frequent misspellings in headers with limited valid values, and numerous security issues such as exposed RFC 1918 addresses and request header echo-back vulnerabilities that revealed other crawlers' IP addresses.