» Tag
security-research
6 postsExploitGym Benchmark Tests If AI Agents Can Build Real Exploits
ExploitGym benchmarks whether AI agents can convert 869 real-world security bugs into working, code-execution-achieving exploits.
FFmpeg's 16-Year-Old MagicYUV Flaw Enables RCE via Crafted Video
A 16-year-old heap overflow in FFmpeg's MagicYUV decoder (CVE-2026-8461) enables RCE via crafted AVI files, hitting Jellyfin, Nextcloud and more.
AI Agents Take on Embedded RTOS Vulnerability Research
How a Codex-based AI agent, Trail of Bits skills, and a custom GDB stub enabled vulnerability research on an eCos cable modem's RTOS firmware.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comHanwha security cameras shipped a GitHub admin token in firmware
A GitHub admin token with access to hundreds of repos was found hardcoded in Hanwha security camera firmware, exposed via a Vite build leak.
CAI Dataset: The Largest Corpus of LLM-Driven Hacker Trajectories
CAI Dataset compiles 230,935 sessions and 26 million prompts from 14 months of cybersecurity LLM operator trajectories, exposing major confidentiality risks.
AI Audit Uncovers Seven Real Bugs in Cloudflare's CIRCL
zkSecurity's AI audit tool found seven real bugs in Cloudflare's CIRCL cryptography library, all now fixed and mostly rewarded via HackerOne.