y0news
AnalyticsDigestsSourcesTopicsRSSAICrypto

#vulnerability News & Analysis

92 articles tagged with #vulnerability. AI-curated summaries with sentiment analysis and key takeaways from 50+ sources.

92 articles
AIBearisharXiv – CS AI · Mar 177/10
🧠

Sirens' Whisper: Inaudible Near-Ultrasonic Jailbreaks of Speech-Driven LLMs

Researchers developed SWhisper, a framework that uses near-ultrasonic audio to deliver covert jailbreak attacks against speech-driven AI systems. The technique is inaudible to humans but can successfully bypass AI safety measures with up to 94% effectiveness on commercial models.

AIBearisharXiv – CS AI · Mar 167/10
🧠

Altered Thoughts, Altered Actions: Probing Chain-of-Thought Vulnerabilities in VLA Robotic Manipulation

Research reveals critical vulnerabilities in Vision-Language-Action robotic models that use chain-of-thought reasoning, where corrupting object names in internal reasoning traces can reduce task success rates by up to 45%. The study shows these AI systems are vulnerable to attacks on their internal reasoning processes, even when primary inputs remain untouched.

CryptoBearishCoinTelegraph · Mar 127/10
⛓️

MediaTek patches bug enabling crypto seed theft in just 45 seconds

Ledger's security team discovered a critical vulnerability in MediaTek's secure boot chain that allows attackers to steal cryptocurrency seed phrases from Android devices in just 45 seconds. MediaTek has since patched the security flaw that could have compromised sensitive crypto wallet information on affected Android devices.

MediaTek patches bug enabling crypto seed theft in just 45 seconds
AIBearisharXiv – CS AI · Mar 127/10
🧠

MCP-in-SoS: Risk assessment framework for open-source MCP servers

Researchers have developed a risk assessment framework for open-source Model Context Protocol (MCP) servers, revealing significant security vulnerabilities through static code analysis. The study found many MCP servers contain exploitable weaknesses that compromise confidentiality, integrity, and availability, highlighting the need for secure-by-design development as these tools become widely adopted for LLM agents.

AIBearisharXiv – CS AI · Mar 127/10
🧠

Targeted Bit-Flip Attacks on LLM-Based Agents

Researchers have introduced Flip-Agent, the first targeted bit-flip attack framework specifically designed to exploit LLM-based agents by manipulating hardware faults. The attack can manipulate both final outputs and tool invocations in multi-stage AI agent pipelines, revealing critical security vulnerabilities in these systems.

AIBearisharXiv – CS AI · Mar 117/10
🧠

Security Considerations for Multi-agent Systems

A comprehensive study reveals that multi-agent AI systems (MAS) face distinct security vulnerabilities that existing frameworks inadequately address. The research evaluated 16 AI security frameworks against 193 identified threats across 9 categories, finding that no framework achieves majority coverage in any single category, with non-determinism and data leakage being the most under-addressed areas.

AIBullishOpenAI News · Mar 97/10
🧠

OpenAI to acquire Promptfoo

OpenAI is acquiring Promptfoo, an AI security platform that specializes in helping enterprises identify and fix vulnerabilities in AI systems during the development process. This acquisition strengthens OpenAI's security capabilities and enterprise offerings.

🏢 OpenAI
AIBearisharXiv – CS AI · Mar 97/10
🧠

Knowing without Acting: The Disentangled Geometry of Safety Mechanisms in Large Language Models

Researchers propose the Disentangled Safety Hypothesis (DSH) revealing that AI safety mechanisms in large language models operate on two separate axes - recognition ('knowing') and execution ('acting'). They demonstrate how this separation can be exploited through the Refusal Erasure Attack to bypass safety controls while comparing architectural differences between Llama3.1 and Qwen2.5.

🧠 Llama
CryptoNeutralBitcoinist · Mar 77/10
⛓️

Bitcoin Faces A New Quantum Era As Giant Computing Facility Breaks Ground

A CoinShares report reveals that only 10,230 Bitcoin out of nearly 20 million in circulation are currently vulnerable to quantum computing attacks. This finding comes as quantum computing facilities continue to expand, raising questions about Bitcoin's long-term security against quantum threats.

Bitcoin Faces A New Quantum Era As Giant Computing Facility Breaks Ground
$BTC
AIBearisharXiv – CS AI · Mar 57/10
🧠

Efficient Refusal Ablation in LLM through Optimal Transport

Researchers developed a new AI safety attack method using optimal transport theory that achieves 11% higher success rates in bypassing language model safety mechanisms compared to existing approaches. The study reveals that AI safety refusal mechanisms are localized to specific network layers rather than distributed throughout the model, suggesting current alignment methods may be more vulnerable than previously understood.

🏢 Perplexity🧠 Llama
AIBearisharXiv – CS AI · Mar 47/103
🧠

Semantic-level Backdoor Attack against Text-to-Image Diffusion Models

Researchers have developed SemBD, a new semantic-level backdoor attack against text-to-image diffusion models that achieves 100% success rate while evading current defenses. The attack uses continuous semantic regions as triggers rather than fixed textual patterns, making it significantly harder to detect and defend against.

AIBearisharXiv – CS AI · Mar 37/104
🧠

VPI-Bench: Visual Prompt Injection Attacks for Computer-Use Agents

Researchers have identified critical security vulnerabilities in Computer-Use Agents (CUAs) through Visual Prompt Injection attacks, where malicious instructions are embedded in user interfaces. Their VPI-Bench study shows CUAs can be deceived at rates up to 51% and Browser-Use Agents up to 100% on certain platforms, with current defenses proving inadequate.

CryptoBearishU.Today · Feb 277/105
⛓️

Quantum Computing Risk to Cryptos, Ledger CTO Flags Key Vulnerability

Ledger's CTO and other experts are warning that quantum computers could eventually become powerful enough to break Elliptic Curve cryptography, which would pose a significant threat to cryptocurrency security. This emerging risk highlights a potential vulnerability in current blockchain infrastructure that could impact the entire crypto ecosystem.

$CRV
AI × CryptoNeutralCoinTelegraph – AI · Feb 277/105
🤖

XRPL Foundation patches ‘critical’ flaw that almost made it to mainnet

The XRPL Foundation successfully patched a critical vulnerability in the Ripple blockchain codebase before it reached mainnet deployment. An AI bug hunter identified the security flaw during code scanning, allowing engineers to fix the issue proactively.

XRPL Foundation patches ‘critical’ flaw that almost made it to mainnet
$XRP
AIBearisharXiv – CS AI · Feb 277/107
🧠

Bob's Confetti: Phonetic Memorization Attacks in Music and Video Generation

Researchers discovered a vulnerability in AI music and video generation systems where phonetic prompts can bypass copyright filters. The 'Adversarial PhoneTic Prompting' attack achieves 91% similarity to copyrighted content by using sound-alike phrases that preserve acoustic patterns while evading text-based detection.

$NEAR$APT
AI × CryptoBearishDL News · Feb 257/103
🤖

AI-powered audit uncovers ‘high-severity’ bug in Ethereum software

Octane Security's AI tool discovered a high-severity bug in Nethermind, a software client that runs the Ethereum blockchain. This represents a significant security vulnerability in critical Ethereum infrastructure that could potentially impact network operations.

$ETH
AI × CryptoBearishDL News · Feb 197/108
🤖

OpenAI releases crypto security tool as Claude blamed for $2.7m Moonwell bug

OpenAI has released a new crypto security tool following a costly incident where AI-generated code from Claude caused a $2.7 million bug that affected Moonwell users. The timing suggests a response to growing concerns about AI-generated code vulnerabilities in cryptocurrency applications.

AINeutralOpenAI News · Nov 77/107
🧠

Understanding prompt injections: a frontier security challenge

Prompt injections represent a significant security vulnerability in AI systems, requiring specialized research and countermeasures. OpenAI is actively developing safeguards and training methods to protect users from these frontier attacks.

CryptoNeutralEthereum Foundation Blog · May 77/103
⛓️

CVE-2025-30147 - The curious case of subgroup check on Besu

CVE-2025-30147 identifies a security vulnerability related to subgroup checks in the Besu Ethereum client. The issue was discovered through collaborative efforts between security researchers and the Besu development team, with proper testing and confirmation processes in place.

CryptoNeutralEthereum Foundation Blog · Mar 217/103
⛓️

Sepolia Incident

A security threat that existed on the Ethereum network from the Merge until the Dencun hard fork has been disclosed, with the vulnerability specifically manifesting during the Sepolia incident. The disclosure highlights a previously unknown attack vector that could have potentially compromised network security during this critical period.

$ETH
CryptoNeutralEthereum Foundation Blog · May 187/102
⛓️

Dodging a bullet: Ethereum State Problems

This article discloses a severe security threat that affected the Ethereum platform until the Berlin hardfork was implemented. The vulnerability represented a clear and present danger to the network's stability and security before being resolved through the protocol upgrade.

$ETH
← PrevPage 2 of 4Next →