CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq, affecting nearly all non-ancient versions. Vendors have been pre-notified, and patches are expected to be released promptly.
lists.thekelleys.org.uk
2 min
1d ago
Mythos, an AI model developed by Anthropic, has demonstrated exceptional ability in identifying security vulnerabilities in source code. Due to its effectiveness, Anthropic has opted to limit access to Mythos, providing it only to selected companies for initial testing and remediation of critical issues.
daniel.haxx.se
10 min
3d ago
CVE-2026-31431 addresses a local privilege escalation vulnerability in Linux, introduced in version 4.14. The issue was linked to commit 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and has been fixed in subsequent releases.
openwall.com
2 min
4/30/2026
A vulnerability in Ramp's Sheets AI allowed for the insertion of formulas that could make external network requests without user approval, posing a risk of data exfiltration through indirect prompt injection. Ramp's security team resolved the issue on March 16, 2026, after it was responsibly disclosed.
promptarmor.com
3 min
4/29/2026
CVE-2026-4747 affects FreeBSD versions 13.5, 14.3, 14.4, and 15.0, specifically when the NFS server with kgssapi.ko loaded is utilized. The vulnerability arises in the svc_rpc_gss_validate() function, which improperly reconstructs an RPC header into a 128-byte stack buffer for GSS-API signature verification.
github.com
14 min
4/1/2026
"Disregard that!" attacks exploit the sharing of context windows in communication, leading to potential security vulnerabilities. These attacks highlight the risks associated with allowing multiple users access to the same AI interaction context.
calpaterson.com
10 min
3/25/2026
OpenClaw, powered by Opus, is generating renewed discussions about autonomous AI agents, similar to the conversations sparked by AutoGPT and BabyAGI in 2023. Current models show significant improvements, but concerns about security vulnerabilities persist.
composio.dev
21 min
3/22/2026
CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq, affecting nearly all non-ancient versions. Vendors have been pre-notified, and patches are expected to be released promptly.
lists.thekelleys.org.uk
2 min
1d ago
CVE-2026-31431 addresses a local privilege escalation vulnerability in Linux, introduced in version 4.14. The issue was linked to commit 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and has been fixed in subsequent releases.
openwall.com
2 min
4/30/2026
CVE-2026-4747 affects FreeBSD versions 13.5, 14.3, 14.4, and 15.0, specifically when the NFS server with kgssapi.ko loaded is utilized. The vulnerability arises in the svc_rpc_gss_validate() function, which improperly reconstructs an RPC header into a 128-byte stack buffer for GSS-API signature verification.
github.com
14 min
4/1/2026
OpenClaw, powered by Opus, is generating renewed discussions about autonomous AI agents, similar to the conversations sparked by AutoGPT and BabyAGI in 2023. Current models show significant improvements, but concerns about security vulnerabilities persist.
composio.dev
21 min
3/22/2026
Mythos, an AI model developed by Anthropic, has demonstrated exceptional ability in identifying security vulnerabilities in source code. Due to its effectiveness, Anthropic has opted to limit access to Mythos, providing it only to selected companies for initial testing and remediation of critical issues.
daniel.haxx.se
10 min
3d ago
A vulnerability in Ramp's Sheets AI allowed for the insertion of formulas that could make external network requests without user approval, posing a risk of data exfiltration through indirect prompt injection. Ramp's security team resolved the issue on March 16, 2026, after it was responsibly disclosed.
promptarmor.com
3 min
4/29/2026
"Disregard that!" attacks exploit the sharing of context windows in communication, leading to potential security vulnerabilities. These attacks highlight the risks associated with allowing multiple users access to the same AI interaction context.
calpaterson.com
10 min
3/25/2026
CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq, affecting nearly all non-ancient versions. Vendors have been pre-notified, and patches are expected to be released promptly.
lists.thekelleys.org.uk
2 min
1d ago
A vulnerability in Ramp's Sheets AI allowed for the insertion of formulas that could make external network requests without user approval, posing a risk of data exfiltration through indirect prompt injection. Ramp's security team resolved the issue on March 16, 2026, after it was responsibly disclosed.
promptarmor.com
3 min
4/29/2026
OpenClaw, powered by Opus, is generating renewed discussions about autonomous AI agents, similar to the conversations sparked by AutoGPT and BabyAGI in 2023. Current models show significant improvements, but concerns about security vulnerabilities persist.
composio.dev
21 min
3/22/2026
Mythos, an AI model developed by Anthropic, has demonstrated exceptional ability in identifying security vulnerabilities in source code. Due to its effectiveness, Anthropic has opted to limit access to Mythos, providing it only to selected companies for initial testing and remediation of critical issues.
daniel.haxx.se
10 min
3d ago
CVE-2026-4747 affects FreeBSD versions 13.5, 14.3, 14.4, and 15.0, specifically when the NFS server with kgssapi.ko loaded is utilized. The vulnerability arises in the svc_rpc_gss_validate() function, which improperly reconstructs an RPC header into a 128-byte stack buffer for GSS-API signature verification.
github.com
14 min
4/1/2026
CVE-2026-31431 addresses a local privilege escalation vulnerability in Linux, introduced in version 4.14. The issue was linked to commit 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and has been fixed in subsequent releases.
openwall.com
2 min
4/30/2026
"Disregard that!" attacks exploit the sharing of context windows in communication, leading to potential security vulnerabilities. These attacks highlight the risks associated with allowing multiple users access to the same AI interaction context.
calpaterson.com
10 min
3/25/2026
No more articles to load