cyber
Sunday-to-Monday onslaught fuels speculation over AI-assisted bug reports
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system.
Its replacement reflects a changing reality for security teams.
OpenAI has officially launched the full version of GPTโ5.5โCyber, a specialized AI model engineered for advanced vulnerability detection, patch generation, and automated remediation at machine speed.
A new open-source bug bounty hunting toolkit called BugHunter, built on top of Anthropicโs Claude Code and now extended to support free AI providers like Ollama and Groq, is gaining traction in the security research community for automating the full vulnerability discovery and reporting pipeline. Developed by security researcher Shuvon Md Shariar Shanaz and hosted [โฆ]
Just a day after Arch Linux developers believed they got their malware AUR incident under control with 1,500+ packages affected by malware, another round of of AUR malware is now being discovered
The US government has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States.
Will Jason Statham save us?
An early update on what we've learned from Project Glasswing.
If any impact is discovered, customers will be notified via established incident response and notification channels.
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts saidโฆ
In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the modelsโ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.
On May 13, 2026, the website SecurityBaseline.eu was launched. It is a spin-off from the Dutch โBasisbeveiligingโ, which has monitored baseline security for over a decade and is part of governmental policy. Three months ago we sent tens of thousands of e-mails to European governments indicating the new site would launch, giving them time to [โฆ]
exploit for CVE-2026-42945. Contribute to DepthFirstDisclosures/Nginx-Rift development by creating an account on GitHub.
A series of unfortunate events.
On 2026-05-11, an attacker chained a pull_request_target Pwn Request, GitHub Actions cache poisoning across the forkโbase trust boundary, and OIDC token extraction from runner memory to publish 84 malicious versions across 42 @tanstack/* packages on npm. Full postmortem.
Contribute to V4bel/dirtyfrag development by creating an account on GitHub.
The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free flaw capable of enabling Remote Code Execution (RCE) in version 2.4.67, released on May 4, 2026.
Copy Fail (CVE-2026-31431): a 732-byte Linux LPE โ straight-line, no race, no per-distro offsets. Same Python script roots Ubuntu, Amazon Linux, RHEL, SUSE since 2017. Page-cache write bypasses on-disk file-integrity tools and crosses container boundaries. Found by Xint Code.