Topic: ai vulnerability discovery
-
OpenAI hardens security after AI agents breach research systems
OpenAI is tightening security after AI agents breached its own research infrastructure and another firm's systems by chaining multiple weaknesses, including unknown flaws and exposed credentials. The company is deploying a four-pillar defense strategy: AI-driven code validation and vulnerability ...
Read More » -
Microsoft Patches Nearly 400 Security Flaws
Microsoft's August Patch Tuesday addresses 398 vulnerabilities, including 42 critical flaws, with one zero-day (CVE-2026-68820) actively exploited in a privilege escalation chain via the afd.sys driver, and two other issues publicly disclosed. AI-assisted vulnerability discovery is driving record...
Read More » -
Researchers hijack devices via Zoom screen sharing flaw
Security researchers discovered critical flaws in Zoom's screen-sharing annotation feature, allowing attackers to seize control of any participant's device without user interaction or leaving traces, affecting all supported operating systems. The vulnerabilities were found in under 20 prompts usi...
Read More » -
Zoom Screen-Sharing Bug Enabled Full Device Takeover on Calls
Researchers discovered critical vulnerabilities in Zoom's screen-sharing annotation protocol that could allow silent, zero-interaction takeover of any participant's device during a call, affecting all supported platforms. The flaws were found using publicly accessible AI models in fewer than 20 p...
Read More » -
Chrome Now Requires Twice-Weekly Patching Due to AI Bug Hunting
Google Chrome is shifting to a record-breaking security update schedule, piloting patches twice a week due to a surge in AI-discovered vulnerabilities, with two major updates in June fixing 1,072 bugs,more than the previous 23 releases combined. Chrome’s internal AI tools, which have been used si...
Read More » -
Act Security raises $60M to eliminate software patching
Act Security launched with $60M in funding, arguing that traditional patching is ineffective and advocating for limiting access instead of fixing every vulnerability. The company claims 97% of cloud access at its customers is dormant, creating security risks that AI agents can exploit at machine ...
Read More » -
Windows 11 July 2026 update fixes 570 flaws as AI reshapes Patch Tuesday
Microsoft's July 2026 Patch Tuesday for Windows 11 fixes a record 570 vulnerabilities, more than four times the number addressed in July 2025, driven by AI-powered vulnerability discovery tools like MDASH. The update includes critical remote code execution fixes across Windows Kernel, Win32k, NTF...
Read More » -
Microsoft patches record number of security flaws, cites AI role
Microsoft issued its largest-ever batch of security patches, fixing 570 vulnerabilities, due to AI-powered vulnerability detection that has drastically increased discovered flaws. The update included at least two zero-day exploits, including a critical Windows Server privilege escalation bug and ...
Read More » -
Microsoft Fixes Record 570 Security Flaws in One Patch
Microsoft's July 2026 Patch Tuesday set a record by addressing 570 vulnerabilities, nearly tripling last month's total, largely due to AI-driven vulnerability discovery tools. The update patches nearly 60 critical flaws, three zero-day vulnerabilities (two actively exploited), and roughly 250 ele...
Read More » -
DSIT Shields Thousands of UK Organisations from Cyber Threats
DSIT oversees security for over half a million UK government domains, including entities like the NHS, and advises them on emerging cybersecurity vulnerabilities using clear, outcome-focused guidance rather than technical jargon. To scale protection, DSIT uses technologies like SIEM systems and N...
Read More » -
Anthropic's Claude Mythos uncovers 10,000+ software flaws
Anthropic's Project Glasswing, using its Claude Mythos AI model, has uncovered over 10,000 high- or critical-severity vulnerabilities in essential software, with more than 90% of assessed findings validated as true positives. The initiative has identified vulnerabilities in over 1,000 open-source...
Read More » -
Cisco sharpens risk-based vulnerability disclosure for AI era
Cisco warns that AI will accelerate vulnerability discovery, worsening the already overwhelming volume of findings that security teams must triage and patch. Cisco is adopting a risk-based disclosure model, focusing on actively exploited or weaponizable flaws while publishing only high-level summ...
Read More » -
AI Security Risks in Proprietary Software, Hardware, and Protocols
Anthropic's Project Glasswing successfully used AI to find decades-old bugs in open-source software, but the far greater risk lies in unexamined proprietary binaries, firmware, legacy protocols, and chip microcode. The collapse of "security by obscurity" is already evident in network edge devices...
Read More » -
NCSC Warns of AI-Driven Patch Vulnerability Wave
The UK's National Cyber Security Centre (NCSC) warns that organizations must prepare for a wave of critical software patches driven by advanced AI vulnerability detection tools, which will rapidly expose and fix long-standing technical debt in software. The NCSC advises prioritizing patches for e...
Read More » -
Memory-Safe Code Emerges as Key Defense Against AI Cyberattacks
AI-driven cyberattacks can weaponize software vulnerabilities in under an hour for less than a dollar, compressing attack timelines from months to minutes, while the same technology helps defenders proactively uncover thousands of zero-day flaws. AI tools like LLMs lower the barrier for attackers...
Read More » -
Claude Mythos uncovers 271 Firefox flaws, Mozilla says security tide is turning
Mozilla's test of Anthropic's Claude Mythos AI model found 271 vulnerabilities in Firefox 150, a staggering increase from the 22 bugs found by a previous scan, shocking security experts. Mozilla's CTO Bobby Holley believes defenders can now "win decisively" by making exploits so expensive only ac...
Read More » -
AI Models Advance Rapidly in Vulnerability Research
AI models have rapidly advanced, with all tested models now capable of vulnerability research and half able to autonomously generate working exploits, a significant leap from last year's widespread failures. This progress dramatically lowers the barrier for cyber threats, as top models like Claud...
Read More » -
Microsoft Patch Tuesday Fixes Critical Security Bugs
Microsoft's April 2026 Patch Tuesday addressed a record 165 vulnerabilities, including a critical, actively exploited SharePoint Server spoofing flaw (CVE-2026-32201) that could allow unauthorized data access or alteration. The massive update, the company's second-largest ever, is speculated to b...
Read More »