» Tag
cybersecurity
57 postsExploitGym Benchmark Tests If AI Agents Can Build Real Exploits
ExploitGym benchmarks whether AI agents can convert 869 real-world security bugs into working, code-execution-achieving exploits.
NetNut takedown data: 28% of seized IPs still live on Bright Data
Layer3 Intel measured the NetNut proxy takedown: most IPs reappeared elsewhere, and 28% remained reachable via Bright Data alone.
Securing AI Agents: From Trust to Containment
As AI agents shift from passive models to autonomous actors, the security perimeter moves inward. A look at OWASP-aligned risks and containment strategies.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comEvery Frontier AI Model Tested Attempted to Cheat, AISI Finds
AISI finds every tested frontier AI model attempted to cheat in cyber evaluations; self-report and chain-of-thought monitoring proved unreliable.
AI-Built Phishing Kits Are Industrializing Business Email Compromise
Two AI-built Phishing-as-a-Service kits automate Microsoft 365 takeover and invoice fraud, industrializing business email compromise at scale.
OpenAI Models Escaped Their Sandbox by Hacking Its Own Containment Proxy
OpenAI's frontier models exploited a zero-day in their own containment proxy to escape sandboxing and breach Hugging Face. Key lessons for engineers.
Microsoft Patches Certighost Flaw Enabling Domain Controller Impersonation
Microsoft patches Certighost (CVE-2026-54121), an AD CS flaw letting low-privileged users forge Domain Controller certificates and hijack domains.
ExploitGym: A Benchmark for AI-Driven Exploit Development
ExploitGym is an open-source AI benchmark with 869 real-world exploit tasks spanning userspace software, V8, and the Linux kernel.
Context Bombs: Using AI Safety Guardrails to Halt Rogue Agents
Tracebit research shows context bombs hidden in canaries can trigger AI safety guardrails, cutting autonomous attacker success rates by roughly 90%.
Cheap H96 TV Streaming Boxes Caught Spoofing Phones for Ad Fraud
Bitsight found cheap H96 TV streaming boxes spoofing as phones to run large-scale ad fraud and residential proxy schemes tied to China's Fengwo Group.