Vulnerability research

Training Frontier Models to Out-Think Hackers — Uri Rolls, Arithmetic & Thom Wolf, Hugging Face

Training Frontier Models to Out-Think Hackers — Uri Rolls, Arithmetic & Thom Wolf, Hugging Face

Thom Wolf and Uri Rolls discuss the critical role of AI in cybersecurity, presenting a new benchmark called Masov. They argue that while frontier models excel at reconnaissance, they lack the sophisticated reasoning to exploit complex, logic-based zero-day vulnerabilities, such as a Keycloak name-versus-ID exploit. The solution, they propose, lies in high-quality, open-source AI models trained on real-world zero-day data to enable defenders to outpace attackers and build a new, AI-native security stack.

Claude Security’s public beta, OpenAI’s five-point plan and cybersecurity’s Y2K moment

Claude Security’s public beta, OpenAI’s five-point plan and cybersecurity’s Y2K moment

Explore the AI industry's "Y2K moment" in cybersecurity, as major players like OpenAI, Anthropic, and CrowdStrike form coalitions to tackle threats. This summary also delves into a new framework for AI agent identity based on Zero Trust principles and analyzes the "Copy Fail" Linux vulnerability, a decade-old flaw uncovered by AI, highlighting the escalating need for proactive vulnerability research.

Beyond phishing: Cyber threats in the age of AI with Four Flynn (pt. 1)

Beyond phishing: Cyber threats in the age of AI with Four Flynn (pt. 1)

VP of Security and Privacy at Google DeepMind, Four Flynn, discusses the landmark 'Operation Aurora' cyberattack, the 'defender's dilemma,' and how AI is now being used both to create novel threats and to build a new generation of defenses to find and automatically patch software vulnerabilities.

Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this Vulnerability

Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this Vulnerability

SMTP smuggling is a critical vulnerability allowing email spoofing that bypasses standard authentication protocols like SPF and DMARC. This research presents a large-scale study on its prevalence, uncovering widespread issues due to shared infrastructure and incomplete patches, and introduces a novel, non-intrusive methodology for ethically testing private email services.