Tag: cves
4 articles

Malicious Extensions Exploit AI Browser Agents
Imagine a single malicious browser extension handing an AI-powered browser agent a set of instructions, allowing it to act with the browser's existing privileges - and putting your entire online presence at risk. Security researcher Gal Weizman has uncovered this vulnerability with his proof-of-concept, BragJack, which can hijack AI assistants embedded in popular Chromium-based browsers.

AI Patches Fall Short Without Human Oversight
Researchers at 1Password's Off-by-1 Labs put AI to the test, generating 6,080 patches for six real vulnerabilities - but here's the catch: human oversight was crucial to ensuring those patches actually worked. Even with advanced models like ChatGPT and Claude Opus, AI patches fell short without a human in the loop.

Linux Kernel Team Floods with 432 CVEs in Two Days
A staggering 432 Linux kernel CVEs were published over just two days, sending shockwaves through the Linux community and leaving system administrators scrambling to keep up with the sudden workload. This unprecedented flood of vulnerability notices has sparked heated debate over prioritization and practical solutions.

Exposure Management Platforms Face Validation Test
Are you tired of filling dashboards with green and closing hundreds of tickets, only to wonder if your organization is truly safer? The harsh reality is that most exposure management platforms fall short in connecting remediation to real risk reduction.