Topic: exploit development
-
Unpatchable 'usbliter8' Exploit Bypasses Apple A12 and A13 SecureROM
Security researchers released usbliter8, a working exploit achieving arbitrary code execution in the SecureROM of Apple's A12 and A13 chips due to a permanent hardware flaw in the Synopsys DWC2 USB controller that no software update can fix. The exploit requires physical possession of the device ...
Read More » -
Researcher Publishes MiniPlasma Windows Exploit for 2020 Bug
A security researcher released the "MiniPlasma exploit", based on 2020 proof-of-concept code, targeting an unpatched Windows flaw from that year that can allow arbitrary code execution or privilege escalation. The exploit highlights the ongoing risk of "unpatched vulnerabilities", as Microsof...
Read More » -
GPT-5.6-Cyber more compliant with security researchers
OpenAI released GPT-5.6-Cyber, a specialized model for zero-day vulnerability discovery and exploit chain construction, offering fewer refusals for high-risk security tasks and restricted to its vetted Daybreak Red tier. The model completed 95% of exploit-related requests versus 1.5% for standard...
Read More » -
Anthropic’s AI Hunts Vulnerabilities for Japanese Banks
Three major Japanese banks (MUFG, Mizuho, SMFG) will join the restricted preview of Anthropic's Claude Mythos, an advanced AI tool for discovering critical security vulnerabilities, marking the first Japanese participation in a program previously limited to US and European partners. The inclusion...
Read More » -
Hacker Groups Unite: Scattered Spider, ShinyHunters, LAPSUS$ Form Alliance
Scattered LAPSUS$ Hunters (SLH) is a confirmed alliance merging the reputations of Scattered Spider, ShinyHunters, and LAPSUS$, signaling a long-term strategic consolidation in the cybercrime world. The group operates through a small core of operators managing multiple personas, using Telegram as...
Read More » -
OpenAI Rolls Out GPT-5.6 Cyber With Two-Tier Access Plan
OpenAI launched GPT-5.6-Cyber, a specialized cybersecurity model built on GPT-5.6 Sol, alongside a restructuring of its Daybreak program into two tiers: Daybreak Blue for defensive operations and Daybreak Red for advanced defensive and authorized offensive work. Daybreak Blue provides access to G...
Read More » -
New Linux Kernel Flaw 'Bad Epoll' Lets Unprivileged Users Get Root on Android
The Bad Epoll vulnerability (CVE-2026-46242) is a use-after-free bug in Linux's epoll feature that allows any unprivileged user to escalate privileges to root, affecting Linux desktops, servers, and Android devices; a patch has been released. The flaw can be triggered from within Chrome's rendere...
Read More » -
CISA Urges Immediate Patch for Exploited Citrix Bleed 2 Vulnerability
Federal agencies and businesses using Citrix NetScaler systems must urgently patch **CVE-2025-5777** after CISA confirmed active attacks, issuing a strict 24-hour deadline for remediation. The vulnerability affects **NetScaler ADC and Gateway devices** running outdated versions, allowing unauthor...
Read More » -
Exploit released for new DirtyDecrypt Linux root flaw
A proof-of-concept exploit called DirtyDecrypt has been released for a Linux kernel privilege escalation vulnerability (CVE-2024-xxxxx) in the rxgk module, allowing attackers to gain full root access on unpatched systems. The vulnerability involves a race condition or memory corruption in cryptog...
Read More » -
Burp Suite Professional 2023: Key Updates & Features
Burp Suite Professional 2023 features an improved scanning engine that delivers faster, more reliable detection of complex vulnerabilities while reducing false positives. The update enhances session handling and authentication support for testing applications with intricate login flows, and boost...
Read More »