GeistHaus
log in · sign up
39 pages link to this URL
AI Slop & the Vulnerability Treadmill

It has not been a relaxing few months for software security teams. In December, React disclosed its first critical CVE: an unauthenticated remote code execution flaw in Server Components. In March, not only was Aqua Security’s Trivy, a widely-used security scanning tool, compromised twice in three weeks through a GitHub Actions misconfiguration, but hackers also

2 inbound links article en
AI Model Discovers 22 Firefox Vulnerabilities in Two Weeks

Claude Opus 4.6 discovered 22 Firefox vulnerabilities in two weeks, including 14 high-severity bugs, as nearly 20% of all critical Firefox vulnerabilities were fixed in 2025. The AI also wrote working exploits for two bugs, demonstrating emerging capabilities that give defenders a temporary advantage but signal an accelerating arms race in cybersecurity.

2 inbound links website en claude ai firefox vulnerabilityDevelopmentAIML & Data EngineeringSecurity VulnerabilitiesMozillaClaudeFirefoxAnthropic
More, and More Extensive, Supply Chain Attacks

Open source components are getting compromised a lot more often. I did some counting, with a combination of searching, memory, and AI assistance, and we had two in 2026-Q1 ( trivy, axios), after four in 2025 ( shai-hulud, glassworm, nx, tj-actions), and very few historically [1]: Earlier attacks were generally compromises of single projects, but some time around Shai-Hulud in 2025-11 there sta

0 inbound links article en airisktech
Anthropic's Mythos set off a cybersecurity 'hysteria.' Experts say the threat was already here

The arrival of Anthropic's Mythos jolted banks, software giants and governments into reckoning with a new era of cyber attacks. But the threat is already here.

2 inbound links article en Technology cnbcArticlesBreaking News: MarketsBanksBreaking News: InvestingInvestment strategyJamie DimonBreaking News: TechnologyTechnologyCybersecuritySam AltmanElon MuskSatya NadellaJPMorgan Chase & CoETFMG Prime Cyber Security ETFFirst Trust NASDAQ Cybersecurity ETFGlobal X Cybersecurity ETFApple IncAmazon.com IncPalo Alto Networks IncInvestingFinanceAI EffectAI AgeAI - Artificial Intelligencesource:tagname:CNBC US Source
Discovering Negative-Days with LLM Workflows

It’s no longer just about reverse-engineering n-days. You can detect vulnerabilities in open-source repositories before a CVE is published - or even if they’re never published. Here’s how I built an LLM workflow to detect “negative-days” and “never-days”.

3 inbound links article en posts appsecdev
We Reproduced Anthropic's Mythos Findings With Public Models

Anthropic framed Mythos and Project Glasswing as proof that frontier AI vulnerability research now needs gated access. We tested the public, patched cases with GPT-5.4 and Claude Opus 4.6 and found that the key building blocks are already accessible outside Glasswing, while reliable operationalization remains the real moat.

2 inbound links article en
At Machine Speed · Matthias Ott

Web design engineer, UX designer, teacher, and speaker – helping teams build websites and digital products with a focus on CSS, accessibility, and performance.

2 inbound links website en AIsecurityopensourceKirbycommunity
The vulnerability landscape in Q1 2026

This report provides statistical data on published vulnerabilities and exploits we researched during Q1 2026. It also includes summary data on the use of C2 frameworks in APT attacks.

0 inbound links article en AIAPTCVEExploit KitsLinuxMicrosoft OfficeMicrosoft WindowsOpen sourceVulnerabilities and exploitsVulnerability Statistics
Claude Opus 4.6

We’re upgrading our smartest model. Across agentic coding, computer use, tool use, search, and finance, Opus 4.6 is an industry-leading model, often by wide margin.

58 inbound links website en
Unsupervised Learning NO. 515

Opus 4.6 Finds Vulns the Way Human Testers Do, The SaaSpocalypse, Malicious OpenClaw Skills, New Urgency in Building, and more

0 inbound links website en artificial intelligencecybersecuritytechnology