Auto mode is now the default in Claude Code for Pro, Max, and Team plans | Claude by Anthropic
Claude Code will soon run auto mode by default for Pro, Max, and Team plans, enabling longer-running autonomous work, and catching more dangerous commands.
Defenders are increasingly turning to LLMs to to generate vulnerability patches. But our research showed that LLMs only successfully generate patches (without materially changing application behavior) 26% of the time.
Linux Wireless Maintainer Takes Firm Stance Against AI/LLM Generated Slop Patches
In addition to the Linux kernel staging area now rejecting AI/LLM-generated patches except for real security fixes, the Linux wireless networking code is also seeing some shifts around how it will deal with AI/LLM generated patches.
Linux Bridge STP Timer Use-After-Free - SSD Secure Disclosure
Summary A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation. A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic STP timers without an IFF_UP guard. The teardown path taken by dellink never synchronously deletes those timers, so … Linux Bridge STP Timer Use-After-Free Read More »
Imagine how open source maintainers feel | Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist.
Discover how to find the best Mario Kart 8 build using the Pareto frontier method. This interactive guide explores multi-objective optimization of speed, acceleration, and other key stats to help you beat your friends on the race track.
Why attacks that look like normal traffic are the hardest to stop. How L3/4 and L7 defenses differ, and what four real DDoS incidents reveal about each.
Massachusetts prosecutors run on dial-up-era software
I asked all 11 Massachusetts DAs for their case data. Six million charges came back. The system holding them is "obsolete" — and its replacement is being bought right now, in silence.
30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next
A security practitioner's account of running Claude Mythos Preview in a vulnerability-hunting harness for 30 days: where it proved exploits and what it cost ($42K).
HashiCorp Ships Public Beta of Vault Kubernetes Key Management
HashiCorp has released a public beta of Vault Kubernetes key management, a KMS v2-compatible plugin that lets the Kubernetes API server delegate envelope encryption to Vault Enterprise, moving the key encryption keys that protect etcd data out of the cluster and into a separately governed trust domain.
The OpenAI Hack Shows the Genie Is Out of the Bottle - Schneier on Security
This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks. Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to ...
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or imported these versions, you must assume your environment is compromised.
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.
NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages | Blog | Endor Labs
We are actively investigating a coordinated malware campaign affecting a broad set of highly downloaded packages by Jared Wray (GitHub) and affecting the cacheable ecosystem.