Vulnerability discovery

Who’s afraid of an open-weight model? GLM, context bombing and post-Black Hat attacks

Who’s afraid of an open-weight model? GLM, context bombing and post-Black Hat attacks

This episode dives into GLM-5.3's advanced vulnerability discovery, debating its potential for good or harm. It then explores "context bombing," an innovative defensive use of prompt injections, and analyzes recent social engineering attacks targeting cybersecurity pros after the Black Hat conference, emphasizing human vulnerability and the need for robust AI defenses.

Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd

Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd

David Brumley discusses the challenges and solutions for teaching AI models to hack, drawing parallels with human learning. He introduces a 'ladder of tasks' approach for reinforcement learning and addresses the critical flaw of traditional benchmarks: measurement difficulties with multiple vulnerabilities and 'reward hacking.' His team's 'Audit Task' uses deterministic graders and precision/recall metrics for open-world assessment. He demonstrates this with an in-depth case study on attacking Chrome's V8 engine, showcasing how advanced models achieve real zero-day exploits, and warns against 'benchmaxxing security' without robust, honest grading.

GLM-5.2: The real security risk? Plus: Vibe hunting, the end of CVSS and updates on Lightwell

GLM-5.2: The real security risk? Plus: Vibe hunting, the end of CVSS and updates on Lightwell

This podcast explores the implications of open-weight AI models like GLM-5.2 for cybersecurity, CISA's new four-variable vulnerability prioritization model, the rise of AI-assisted 'vibe hunting,' and the commercial launch of IBM and Red Hat's Lightwell for securing open-source software. It highlights the tension between AI capabilities for attackers and defenders, the challenges of rapid vulnerability remediation, and the need for new "trust infrastructures" in the AI era.

The AI bugpocalypse is here. Now what? - Jack Cable, Corridor

The AI bugpocalypse is here. Now what? - Jack Cable, Corridor

Jack Cable discusses the "AI bug apocalypse" driven by advanced AI models finding and exploiting vulnerabilities and AI coding tools increasing attack surfaces. He champions a "secure by design" approach, advocating for systemic changes like using memory-safe languages to prevent common vulnerability classes rather than just patching. He also addresses AI's role in introducing new vulnerabilities, the shift towards autonomous AI in development, and policy recommendations for securing the future of AI-powered coding.

Inside Mythos: Anthropic's Locked-Down Frontier Model — with Jon Krohn (@JonKrohnLearns)

Inside Mythos: Anthropic's Locked-Down Frontier Model — with Jon Krohn (@JonKrohnLearns)

Anthropic's Claude Mythos Preview is a frontier AI model with emergent hacking capabilities so advanced it's being withheld from public release. This summary details its near 100x performance leap in exploit generation, the 'Project Glasswing' industry consortium for responsible disclosure, and practical advice for developers to secure AI-generated code in this new era of automated vulnerability discovery.