Articles Tagged “Responsible Disclosure”
14 articles found

Mandiant AI Agents Found 100 Critical Flaws in 2 Days
Google's Mandiant published its AVDH blueprint after the agent pipeline verified 100+ critical vulnerabilities in 48 hours and produced 12 assigned CVEs.

AI Agent Memory Files: One Prompt Blocks the Spread
Anthropic and EPFL found payloads spread between AI agents via editable memory files, and a one-paragraph prompt warning cut the spread to near zero.

Linux Kernel SCTP Fix Lands in All Stable Branches
An 18-year-old SCTP use-after-free went from private report to patched across every supported Linux stable branch in a little over three weeks flat.

HTTP Terminator Hunts Request Smuggling Bugs With AI
PortSwigger open-sourced HTTP Terminator, an AI research system that generated 30,000 desync vectors and surfaced a now-patched Apache zero-day.

Securing AI Coding Agents in CI: A Hardening Guide
Black Hat 2026 showed a single GitHub issue could reach CI secrets. Here are seven hardening steps for AI coding agents, plus the patched version numbers.

Next.js Ships First Pre-Announced Security Update
Next.js patched 9 CVEs in v16.2.11 and v15.5.21 — its first pre-announced monthly security release, giving teams time to plan upgrades before disclosure.

7-Zip 26.02 Patches an Archive Decoder Flaw via ZDI
7-Zip 26.02 fixes a heap overflow in the XZ decoder, found by researcher Landon Peng and coordinated through ZDI as advisory ZDI-26-444. Update manually.

cURL 8.21.0 Ships a Record 18 Fixes, Including a 25-Year-Old Bug
cURL 8.21.0 patched a record 18 vulnerabilities on June 24, 2026, including a 25-year-old flaw surfaced by AI-assisted code analysis, before any exploitation.

Responsible Disclosure Helps Secure Dify, an AI Platform Powering 1M+ Apps
Security researchers responsibly disclosed the DifyTap flaws in the popular Dify AI platform on June 22, 2026 — and fixes shipped quickly, protecting more than a million AI apps.

AI-Assisted Research Helps Fix a 29-Year-Old Squid Proxy Flaw Before Attackers Found It
Researchers used AI to help uncover and responsibly disclose Squidbleed, a memory-leak flaw lurking in the Squid web proxy since 1997 — and the coordinated fix shipped before any known exploitation.

Project Lightwell: IBM and Red Hat's $5B AI Open-Source Security Push
IBM and Red Hat launch Project Lightwell, a $5B AI-powered open-source security effort that validates fixes at scale and feeds patches upstream.

Anthropic Opens Glasswing — Mythos Cyber Findings Can Now Be Shared With the Wider Defensive Community
On May 19, 2026, Anthropic updated the Glasswing program so partners can now share Mythos-derived cyber findings, tools, and code with the wider defensive community for maximum security impact.

Microsoft's Zero Day Quest 2026 Pays $2.3M to Researchers Who Hardened Cloud and AI
Microsoft's Zero Day Quest 2026 awarded $2.3 million across 80+ high-impact cloud and AI vulnerabilities — turning hacker creativity into a stronger Secure Future Initiative.

An AI Agent Just Found Its First Critical CVE — XBOW Autonomously Discovers a 9.8-Severity Microsoft Vulnerability
XBOW, a fully autonomous AI penetration testing agent, independently discovered CVE-2026-21536, a critical RCE flaw in a Microsoft service — marking a milestone for AI-powered defense.
