Microsoft is threatening legal action for disclosing exploits
… They’ve employed people who have publicly posted zero-day exploits, some with criminal hacking convictions on their record. Microsoft has also purchased exploits from brokers. …
… They’ve employed people who have publicly posted zero-day exploits, some with criminal hacking convictions on their record. Microsoft has also purchased exploits from brokers. …
… That means there’s also the risk of malicious actors using them for ill purposes, such as creating exploits for oppressive regimes or stealing sensitive data on their own. Industry experts predict that the advancement in AI security capabilities is going to lead to a lot more exploits. …
… The report also mentions AI as a target for attackers, saying “GTIG has observed adversaries increasingly target the integrated components that grant AI systems their utility, such as autonomous skills and third-party data connectors.” Google’s report also details how hackers are using “persona-dri… …
Nearly every Linux distribution released since 2017 is currently vulnerable to a security bug called “Copy Fail” that allows any user to give themselves administrator privileges. …
Researchers at the security firm Calif say they used Anthropic’s cybersecurity AI to create a privilege escalation exploit, the Wall Street Journal reports: Last September, Apple said it leveraged its hardware and operating system expertise into a technology called Memory Integrity Enforcement MIE …
… Gergely Orosz, the creator of The Pragmatic Engineer newsletter, writes on X that Instagram’s trust and safety team was “absolutely gutted” over the last several weeks due to layoffs and reassignments to tasks like AI labeling. “Apparently this was not a sophisticated hack,” Orosz writes. “But engi…
Claude Security uses the Opus 4.7 model to scan a business’s codebase for vulnerabilities and issue a fix. …
… I wrote about the cybersecurity time bomb of AI browsers for The Verge last year. …
Security Cybersecurity is the rickety scaffolding supporting everything you do online. …
… Wiz Research used AI models to uncover a vulnerability in GitHub’s internal git infrastructure that could have allowed attackers to access millions of public and private code repositories. “Our security team immediately began validating the bug bounty report. …