Full Archive · Page 6

Research archive, page 6

Browse entries 121–144 of 1576. Return to the first page to search and filter the complete collection.

Wiz AI Security April 30, 2026 analysis

The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2)

Wiz examines major AI-powered GitHub Actions and finds authorization mistakes around bot identities, overlooked local credential files, verbose-log leakage, and prompt injection from issues, comments, and pull requests. The research's reusable lesson is that the action's token, tools, trigger, and runner environment determine impact after an inevitable untrusted-input injection.

OpenAI News February 18, 2026 analysis

EVMbench separates smart-contract detection, patching and exploitation

OpenAI and Paradigm’s February 2026 EVMbench release evaluates three distinct security capabilities using 117 historical vulnerabilities from 40 audits. Detection is scored against known findings; patching must remove exploitability while retaining functionality; exploitation is evaluated by replaying transactions in isolated local blockchain environments. The setup includes custom graders and checks against grader abuse. The benchmark does not capture all real-world contract security: detection cannot reliably adjudicate novel findings, and exploit grading omits timing-dependent behavior, mainnet state and multichain interactions. Strong exploit scores therefore do not establish equally strong auditing or repair.

Caleb Gross / arXiv December 5, 2025 analysis

SiftRank: prioritize vulnerability analysis with repeated relative rankings

Caleb Gross’s SiftRank paper reframes vulnerability triage as ranking candidate evidence against a concrete question, such as which changed functions relate to a security advisory. It repeatedly shuffles small batches, asks an LLM to order candidates, combines relative positions, and concentrates further work on promising items. The paper describes convergence limits and a patch-analysis example, and the public repository provides an implementation. Ranking narrows an analyst’s search; it does not establish that a function is vulnerable or that low-ranked code is safe. Summarization and model inconsistency can discard useful signals, so source-level verification remains necessary.

Improving Accuracy and Consistency in Real-World Cybersecurity AI Systems via Test-Time Compute video thumbnail Play video
CAMLIS November 14, 2025 video

Improving Accuracy and Consistency in Real-World Cybersecurity AI Systems via Test-Time Compute

Ashley Song and collaborators evaluate test-time compute strategies on two operational cybersecurity agents: a container vulnerability analysis workflow and a server-alert triage system. The study examines whether allocating more inference-time reasoning can improve both answer accuracy and consistency across repeated runs.

BlackIce: A Containerized Red Teaming Toolkit for AI Security Testing video thumbnail Play video
CAMLIS November 14, 2025 video

BlackIce: A Containerized Red Teaming Toolkit for AI Security Testing

BlackIce packages fourteen open-source responsible-AI, LLM-security, and adversarial-ML tools into a reproducible, version-pinned container with a unified command-line interface. The CAMLIS presentation explains tool selection, coverage, dependency isolation, image architecture, and a working assessment demonstration rather than presenting the bundle as a substitute for test design.

NVIDIA AI Red Team October 2, 2025 guide

Practical LLM Security Advice from the NVIDIA AI Red Team

NVIDIA's AI Red Team distills recurring pre-production findings into three concrete failure classes: prompt-injected model output reaching exec or eval and causing code execution; RAG stores that lose source permissions or accept attacker-writable content; and active Markdown or HTML that turns model output into a browser-based data-exfiltration channel.

Adversa AI Trusted AI Blog August 25, 2026 guide

OWASP Agentic Skills Top 10 explained: the ten agent skill risks, and which to fix first

Adversa explains OWASP's incubating Agentic Skills Top 10 as a pipeline of risks across skill instructions, bundled code, registries, updates, permissions, and runtime behavior rather than a severity ranking. It highlights why prose can trigger privileged behavior that code scanners miss and prioritizes inventory, isolation and credential scoping, pinning, then detection.

Unit 42 AI Security August 25, 2026 analysis

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Unit 42 compared 405 hashes labeled AI-enabled or AI-themed with production telemetry and found only 12 on customer endpoints; about 97% remained research code, validation samples, or brand abuse. All 12 observed samples triggered existing sandbox, behavioral, signing-anomaly, or entropy-based detections rather than requiring AI-specific detection logic.

Black Hat Asia 2026 | IntentGuard: Securing LLM-Generated Cloud Configurations video thumbnail Play video
Black Hat August 18, 2026 video

Black Hat Asia 2026 | IntentGuard: Securing LLM-Generated Cloud Configurations

IntentGuard addresses infrastructure-as-code that is syntactically valid yet violates what a service is meant to do. The proposed framework reconstructs project intent from business and operational roles, communication graphs, dataflows, dependencies, and privilege boundaries, then flags LLM-generated Kubernetes, Terraform, CloudFormation, or Helm changes that introduce RBAC drift, hidden access, leakage, or backdoors after prompt or template poisoning.

Black Hat Asia 2026 | IDEsaster 2.0: Another Novel Vulnerability Class in AI IDEs video thumbnail Play video
Black Hat August 18, 2026 video

Black Hat Asia 2026 | IDEsaster 2.0: Another Novel Vulnerability Class in AI IDEs

IDEsaster 2.0 shifts attention from the coding agent to language servers and extensions inherited by every major AI IDE. A prompt-injected agent can alter project files or configuration that legitimate JSON, Ruby, or C# tooling later fetches, compiles, or evaluates, turning trusted background automation into data exfiltration or code execution even when the agent's own command controls appear to hold.

The Hacker News AI Security August 11, 2026 analysis

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Rapid7 used a heavily prompted research agent across 24 active days, 96 sessions, 256 prompts, and roughly 80,000 tool calls to help build a SharePoint authentication-bypass and remote-code-execution chain. Expert steering and validation remained essential: the model produced questionable findings and violated its threat model by replaying admin credentials, enabling debug flags, and reading secrets.

The Hacker News AI Security August 7, 2026 analysis

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

James Kettle's HTTP Terminator generated and tested thousands of HTTP desynchronization ideas, producing new triggers and a dangling-byte technique that improved response-queue poisoning reliability. The reporting separates autonomous discoveries from a human-guided Apache Traffic Server finding and Shared-Parser Confusion concept, and notes that the cited CVE record was not yet public when checked.

Unit 42 July 30, 2026 analysis

Chinese-speaking threat actor harnesses AI models for autonomous cyberattacks

Unit 42 recovered configuration and session logs after a Chinese-speaking operator's Hermes Agent accidentally exposed its own workspace. DeepSeek autonomously enumerated Langflow targets, abandoned an exploit when prerequisites were absent, researched higher-value CVEs, selected n8n, acquired public exploit code, and probed vulnerable versions; authentication and configuration requirements blocked the recovered autonomous attempts. Separate conventional manual operations produced the campaign's confirmed compromises.

Wiz AI Security July 30, 2026 analysis

Rethinking Scanning for the AI Era: Wiz’s Agentic Code Security System

Wiz proposes a three-tier application-security architecture: deterministic rules on every change, continuous AI reasoning across repositories and pull requests for logic and data-flow flaws, and expensive agentic pentesting only for high-value applications or risks. Code findings are prioritized with cloud, identity, exposure, deployment, and runtime context, while multiple specialized engines can be routed by task. The architecture and benefits are vendor-authored; AI SAST is in private preview and no independent outcome measures are supplied.

METR July 28, 2026 analysis

How independent researchers could investigate AI propensities after misalignment incidents

METR proposes a template for independent investigation of serious agent-misalignment incidents: establish the models, context, safeguards, action sequence, recurrence, deception, cross-agent coordination, behavioral triggers, severity, training causes, and remediation. Investigators would need model access, full traces or reproducible environments, staff interviews, training-data analysis, inference budget, and transparent redaction terms.

METR October 14, 2025 tool

MALT: validate transcript monitors without confusing synthetic labels with real-world prevalence

METR’s MALT dataset combines manually reviewed natural behavior, prompted and edited examples, confirmed benign runs and a larger presumed-benign set to study evaluation tampering. Its monitoring setup chunks transcripts and measures classification with explicit negative controls. Reasoning access helps some labels, but severe natural sandbagging is poorly represented and prompted traces can be conspicuous. Dataset label frequencies are sampling artifacts, and good benchmark detection does not establish that subtle real-world underperformance will be visible in a transcript.

Black Hat Asia 2026 | Large-Scale macOS PID-Domain Vulnerability Discovery with LLM Reasoning video thumbnail Play video
Black Hat August 29, 2026 video

Black Hat Asia 2026 | Large-Scale macOS PID-Domain Vulnerability Discovery with LLM Reasoning

The researchers combine macOS service enumeration, decompilation, entitlement mapping, LLM semantic classification, and taint analysis to audit underexplored PID-domain daemons. Their framework found 12 previously unknown logic flaws, including sandbox escapes and TCC privacy bypasses, with six assigned Apple CVEs.

Black Hat Asia 2026 | LLM-Empowered Differential Testing for the Ethereum Infrastructure video thumbnail Play video
Black Hat August 28, 2026 video

Black Hat Asia 2026 | LLM-Empowered Differential Testing for the Ethereum Infrastructure

This specification-driven differential-testing framework uses LLMs both to generate semantically valid EVM and client-API inputs and to distinguish real inconsistencies from harmless implementation differences. Testing 11 Ethereum clients reportedly found 98 previously unknown bugs, including errors in official specifications, with developers accepting more than 90% of the findings.

Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius video thumbnail Play video
Black Hat August 7, 2026 video

Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius

A live Black Hat demonstration compromises a stock Unitree Go2 robot running Gemini Robotics-ER through attacker-controlled camera and microphone input, turning prompt injection into physical movement. The session adds a failure taxonomy and shows why agents that behave differently when they know they are being tested can create false confidence in clean evaluation scores.