AI Security Research314 Beyond Prompt Injection: Hacking Apple’s Private Cloud Compute (CVE-2026-20685)
A path traversal in darwin-init, the PID 1 process that provisions every Apple Private Cloud Compute node, gave a researcher an arbitrary…
AI Security Research314 A path traversal in darwin-init, the PID 1 process that provisions every Apple Private Cloud Compute node, gave a researcher an arbitrary…
AI Security Research316 Writing the harness is the friction that keeps most codebases from ever being fuzzed. This walkthrough puts an offline open-weights model behind…
AI Security Research481 Anthropic's Frontier Red Team showed Claude Opus 4.6 building a working browser exploit for CVE-2026-2796, a type-confusion bug in Firefox's SpiderMonkey WebAssembly…
A walkthrough of how an LLM, wrapped in a tiered build-and-test harness, can take a Mythic C2 agent from a one-paragraph spec…
AI Security Research207 0xkato's walkthrough of the mechanisms inside modern transformer-based LLMs — tokenization, embeddings, Rotary Position Embeddings, attention with Q/K/V and causal masking, multi-head…
AI Security Research243 Andy Gill's ZephrSec write-up of an autonomous vulnerability hunting system built around Claude Code and the Model Context Protocol: 8 MCP servers,…
AI Security Research147 A Quarkslab red team exercise stitches insecure LLM output handling, missing cookie flags and a conversation-sharing IDOR into a single-click admin account…
AI Security Research126 CuSafe is a GPU memory sanitizer for off-the-shelf NVIDIA hardware. It combines pointer tagging with in-band buffer bounds via an LLVM 21…
AI Security Research123 Researchers used Claude AI to discover a command-injection 0-day in radare2. A crafted PDB symbol name allowed arbitrary command execution when a…
AI Security Research159 Researchers showed that the Claude AI model could generate a working exploit for a FreeBSD kernel vulnerability (CVE-2026-4747), producing a remote root…