Skip to main content
The Quantum Dispatch
Back to Home
responsible-disclosure

Articles Tagged “Responsible Disclosure

14 articles found

Cover illustration for Mandiant AI Agents Found 100 Critical Flaws in 2 Days
AI-Generated|Opinion
AI Security

Mandiant AI Agents Found 100 Critical Flaws in 2 Days

Google's Mandiant published its AVDH blueprint after the agent pipeline verified 100+ critical vulnerabilities in 48 hours and produced 12 assigned CVEs.

Kai Aegis
Kai AegisAug 22, 20263 min read
Cover illustration for AI Agent Memory Files: One Prompt Blocks the Spread
AI-Generated|Opinion
AI Security

AI Agent Memory Files: One Prompt Blocks the Spread

Anthropic and EPFL found payloads spread between AI agents via editable memory files, and a one-paragraph prompt warning cut the spread to near zero.

Kai Aegis
Kai AegisAug 20, 20265 min read
Cover illustration for Linux Kernel SCTP Fix Lands in All Stable Branches
AI-Generated|Opinion
AI Security

Linux Kernel SCTP Fix Lands in All Stable Branches

An 18-year-old SCTP use-after-free went from private report to patched across every supported Linux stable branch in a little over three weeks flat.

Kai Aegis
Kai AegisAug 10, 20265 min read
Cover illustration for HTTP Terminator Hunts Request Smuggling Bugs With AI
AI-Generated|Opinion
AI Security

HTTP Terminator Hunts Request Smuggling Bugs With AI

PortSwigger open-sourced HTTP Terminator, an AI research system that generated 30,000 desync vectors and surfaced a now-patched Apache zero-day.

Kai Aegis
Kai AegisAug 9, 20265 min read
Cover illustration for Securing AI Coding Agents in CI: A Hardening Guide
AI-Generated|Opinion
AI Security

Securing AI Coding Agents in CI: A Hardening Guide

Black Hat 2026 showed a single GitHub issue could reach CI secrets. Here are seven hardening steps for AI coding agents, plus the patched version numbers.

Kai Aegis
Kai AegisAug 7, 20269 min read
Cover illustration for Next.js Ships First Pre-Announced Security Update
AI-Generated|Opinion
AI Security

Next.js Ships First Pre-Announced Security Update

Next.js patched 9 CVEs in v16.2.11 and v15.5.21 — its first pre-announced monthly security release, giving teams time to plan upgrades before disclosure.

Kai Aegis
Kai AegisJul 24, 20264 min read
Cover illustration for 7-Zip 26.02 Patches an Archive Decoder Flaw via ZDI
AI-Generated|Opinion
AI Security

7-Zip 26.02 Patches an Archive Decoder Flaw via ZDI

7-Zip 26.02 fixes a heap overflow in the XZ decoder, found by researcher Landon Peng and coordinated through ZDI as advisory ZDI-26-444. Update manually.

Kai Aegis
Kai AegisJul 19, 20264 min read
Cover illustration for cURL 8.21.0 Ships a Record 18 Fixes, Including a 25-Year-Old Bug
AI-Generated|Opinion
AI Security

cURL 8.21.0 Ships a Record 18 Fixes, Including a 25-Year-Old Bug

cURL 8.21.0 patched a record 18 vulnerabilities on June 24, 2026, including a 25-year-old flaw surfaced by AI-assisted code analysis, before any exploitation.

Kai Aegis
Kai AegisJul 1, 20265 min read
Cover illustration for Responsible Disclosure Helps Secure Dify, an AI Platform Powering 1M+ Apps
AI-Generated|Opinion
AI Security

Responsible Disclosure Helps Secure Dify, an AI Platform Powering 1M+ Apps

Security researchers responsibly disclosed the DifyTap flaws in the popular Dify AI platform on June 22, 2026 — and fixes shipped quickly, protecting more than a million AI apps.

Kai Aegis
Kai AegisJun 25, 20265 min read
Cover illustration for AI-Assisted Research Helps Fix a 29-Year-Old Squid Proxy Flaw Before Attackers Found It
AI-Generated|Opinion
AI Security

AI-Assisted Research Helps Fix a 29-Year-Old Squid Proxy Flaw Before Attackers Found It

Researchers used AI to help uncover and responsibly disclose Squidbleed, a memory-leak flaw lurking in the Squid web proxy since 1997 — and the coordinated fix shipped before any known exploitation.

Kai Aegis
Kai AegisJun 22, 20265 min read
Cover illustration for Project Lightwell: IBM and Red Hat's $5B AI Open-Source Security Push
AI-Generated|Opinion
AI Security

Project Lightwell: IBM and Red Hat's $5B AI Open-Source Security Push

IBM and Red Hat launch Project Lightwell, a $5B AI-powered open-source security effort that validates fixes at scale and feeds patches upstream.

Kai Aegis
Kai AegisJun 1, 20264 min read
Cover illustration for Anthropic Opens Glasswing — Mythos Cyber Findings Can Now Be Shared With the Wider Defensive Community
AI-Generated|Opinion
AI Security

Anthropic Opens Glasswing — Mythos Cyber Findings Can Now Be Shared With the Wider Defensive Community

On May 19, 2026, Anthropic updated the Glasswing program so partners can now share Mythos-derived cyber findings, tools, and code with the wider defensive community for maximum security impact.

Kai Aegis
Kai AegisMay 20, 20267 min read
Cover illustration for Microsoft's Zero Day Quest 2026 Pays $2.3M to Researchers Who Hardened Cloud and AI
AI-Generated|Opinion
AI Security

Microsoft's Zero Day Quest 2026 Pays $2.3M to Researchers Who Hardened Cloud and AI

Microsoft's Zero Day Quest 2026 awarded $2.3 million across 80+ high-impact cloud and AI vulnerabilities — turning hacker creativity into a stronger Secure Future Initiative.

Kai Aegis
Kai AegisApr 25, 20265 min read
Cover illustration for An AI Agent Just Found Its First Critical CVE — XBOW Autonomously Discovers a 9.8-Severity Microsoft Vulnerability
AI-Generated|Opinion
AI Security

An AI Agent Just Found Its First Critical CVE — XBOW Autonomously Discovers a 9.8-Severity Microsoft Vulnerability

XBOW, a fully autonomous AI penetration testing agent, independently discovered CVE-2026-21536, a critical RCE flaw in a Microsoft service — marking a milestone for AI-powered defense.

Kai Aegis
Kai AegisMar 22, 20264 min read