y0news
AnalyticsDigestsSourcesTopicsRSSAICrypto

#vulnerability-disclosure News & Analysis

17 articles tagged with #vulnerability-disclosure. AI-curated summaries with sentiment analysis and key takeaways from 50+ sources.

17 articles
AIBearishFortune Crypto · Apr 10🔥 8/10
🧠

The AI that found 27-year-old vulnerabilities no human ever caught before just forced an emergency meeting with every major Wall Street CEO

Anthropic's latest AI model discovered 27-year-old security vulnerabilities that human researchers missed, prompting Treasury Secretary Scott Bessent and Fed Chair Jerome Powell to convene an emergency meeting with major Wall Street CEOs. The incident highlights critical gaps in legacy system security and raises questions about AI's expanding role in identifying financial infrastructure risks.

The AI that found 27-year-old vulnerabilities no human ever caught before just forced an emergency meeting with every major Wall Street CEO
🏢 Anthropic
AI × CryptoBearishCoinDesk · 2d ago7/10
🤖

AI exposed a massive flaw in top crypto network and experts warn banks could be next

An AI model discovered a critical vulnerability in Zcash that persisted undetected for four years, prompting security researchers to warn that similar hidden flaws likely exist across cryptocurrency networks and traditional financial systems. The incident highlights both AI's value in identifying security threats and the broader vulnerability landscape in digital finance infrastructure.

AI exposed a massive flaw in top crypto network and experts warn banks could be next
AIBearisharXiv – CS AI · 3d ago7/10
🧠

MaskForge: Structure-Aware Adaptive Attacks for Jailbreaking Diffusion Large Language Models

Researchers introduce MaskForge, a black-box attack method that exploits structural vulnerabilities in diffusion-based large language models (dLLMs) by leveraging their native masking capabilities. The technique achieves 79.3% average success rates across five models and transfers effectively to other benchmarks, demonstrating a significant security gap in an emerging class of language models distinct from standard autoregressive architectures.

GeneralBearishCrypto Briefing · May 307/10
📰

Microsoft threatens legal action against researcher Nightmare Eclipse for exploit disclosure

Microsoft has threatened legal action against security researcher Nightmare Eclipse for disclosing an exploit, raising concerns about the chilling effect such threats may have on vulnerability reporting and security research. The incident highlights tensions between corporate legal strategies and the security community's responsible disclosure practices.

Microsoft threatens legal action against researcher Nightmare Eclipse for exploit disclosure
AIBearisharXiv – CS AI · May 277/10
🧠

Red-Teaming Claude Opus and ChatGPT-based Security Advisors for Trusted Execution Environments

Researchers red-teamed ChatGPT and Claude Opus as TEE security advisors, finding both LLMs hallucinate mechanisms and overclaim guarantees in sensitive infrastructure guidance. The study demonstrates some failure patterns transfer across models (up to 12%) and proposes an 80.62% failure reduction through policy gating, retrieval grounding, and verification checks.

🧠 ChatGPT🧠 Claude
AIBearisharXiv – CS AI · May 127/10
🧠

Control Your View: High-Resolution Global Semantic Manipulation in Learned Image Compression

Researchers have developed PGD²-GSM, a novel adversarial attack method that successfully performs high-resolution global semantic manipulation on learned image compression systems for the first time. The breakthrough uses a Periodic Geometric Decay schedule to overcome limitations in existing attack methods, exposing a critical vulnerability in DNN-based compression systems that previous techniques could not achieve.

AIBearisharXiv – CS AI · May 127/10
🧠

MonitoringBench: Semi-Automated Red-Teaming for Agent Monitoring

Researchers introduce MonitoringBench, a semi-automated red-teaming methodology that reveals significant gaps in AI agent monitoring systems. By decomposing attack generation into strategy, execution, and refinement stages, the team created 2,644 adversarial trajectories showing that frontier monitors claiming 94.9% catch rates actually perform at 60.3% against sophisticated attacks.

AIBearisharXiv – CS AI · Apr 207/10
🧠

HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents?

Researchers have identified that 4.93% of skills in major LLM agent ecosystems are harmful and can be weaponized for cyberattacks, fraud, and privacy violations. The study reveals that presenting harmful tasks through pre-installed skills dramatically reduces AI model refusal rates, with harm scores increasing from 0.27 to 0.76 when intent is implicit rather than explicit.

AIBearishThe Register – AI · Apr 197/10
🧠

I meant to do that! AI vendors shrug off responsibility for vulns

AI vendors are increasingly deflecting responsibility for security vulnerabilities in their systems, claiming they are not liable for exploits or misuse. This trend raises concerns about accountability in the rapidly expanding AI industry and creates potential gaps in security standards.

AIBearishDecrypt · Apr 177/10
🧠

Anthropic’s Alarming Mythos Findings Replicated With Off-the-Shelf AI, Researchers Say

Security researchers demonstrated that Anthropic's recently publicized Mythos vulnerability findings can be replicated using commercially available AI models like GPT-5.4 and Claude Opus 4.6 for under $30 per scan, suggesting the security issues may be more widespread than initially suggested.

Anthropic’s Alarming Mythos Findings Replicated With Off-the-Shelf AI, Researchers Say
🏢 Anthropic🧠 GPT-5🧠 Claude
AIBearisharXiv – CS AI · Apr 137/10
🧠

Re-Mask and Redirect: Exploiting Denoising Irreversibility in Diffusion Language Models

Researchers demonstrate a critical vulnerability in diffusion-based language models where safety mechanisms can be bypassed by re-masking committed refusal tokens and injecting affirmative prefixes, achieving 76-82% attack success rates without gradient optimization. The findings reveal that dLLM safety relies on a fragile architectural assumption rather than robust adversarial defenses.

AIBearishBlockonomi · Apr 107/10
🧠

Why Did Federal Officials Urgently Summon Banking CEOs Over Anthropic’s Mythos AI?

U.S. Treasury and Federal Reserve officials convened urgent meetings with major banking CEOs regarding Anthropic's Mythos AI system, which possesses the capability to identify and exploit vulnerabilities in critical financial infrastructure. The high-level engagement signals government concern about AI-driven cybersecurity risks to the banking sector.

🏢 Anthropic
CryptoNeutralCoinDesk · 6d ago6/10
⛓️

Whitehat developer unlocks $2 million stuck in a 2016 Ethereum ICO contract for nine years

Security researcher 0xflorent discovered an integer-overflow vulnerability in a 2016 HongCoin ICO contract, enabling the recovery of $2 million in trapped funds for 48 original investors after nine years. This marks the second high-profile fund recovery the developer has publicized in eight days, highlighting ongoing security risks in legacy smart contracts.

Whitehat developer unlocks $2 million stuck in a 2016 Ethereum ICO contract for nine years
$ETH
GeneralBearishArs Technica – AI · May 186/10
📰

Bug bounty businesses bombarded with AI slop

Bug bounty platforms are being overwhelmed by low-quality AI-generated submissions that waste time and resources, straining corporate vulnerability disclosure programs. This surge reflects broader challenges in maintaining security reward schemes as AI tools democratize report generation without improving actual security research quality.

Bug bounty businesses bombarded with AI slop
DeFiNeutralcrypto.news · May 116/10
💎

Renegade recovers $190K after whitehat returns stolen crypto

Renegade.fi recovered approximately $190,000 after a whitehat hacker exploited a vulnerability in its Arbitrum-based dark pool and voluntarily returned over 90% of the $209,000 drained assets. The incident highlights both the security risks in decentralized finance protocols and the emerging practice of ethical hackers responsibly disclosing vulnerabilities.

Renegade recovers $190K after whitehat returns stolen crypto
$ARB
AINeutralOpenAI News · Jun 95/107
🧠

Scaling security with responsible disclosure

OpenAI has launched its Outbound Coordinated Disclosure Policy to establish a framework for responsibly reporting security vulnerabilities found in third-party software. The policy emphasizes integrity, collaboration, and proactive security measures as OpenAI scales its operations.

GeneralNeutralOpenAI News · Sep 224/106
📰

Outbound coordinated vulnerability disclosure policy

This appears to be a policy document or announcement regarding outbound coordinated vulnerability disclosure procedures. The brief title suggests it outlines protocols for responsibly reporting and coordinating the disclosure of security vulnerabilities to external parties.