Codex with GPT-6 Sol scores 72.1% FuncPass and 25.1% SecPass for $104 on Azure — 78% cheaper than Astra ($468) — with zero confirmed cheating.
I found a flaw in brig where an agent inside the sandbox plants a symlink resulting in an arbitrary host directory with read-write abilities in and out of the sandbox. Tracked as GHSA-wp6x-29qx-fpr7 ...
A capable frontier model isn’t a controlled system. Here are seven questions security teams should answer before they trust AI coding agents with consequential work.
From September 11th, if a vulnerability in a product you sell into the EU is being actively exploited, you have 24 hours to tell a regulator about it. That is the part of the EU Cyber Resilience Act ...
jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic ...
https://github.com/Serotav/Writeups/blob/77556c57999805fa7815a114da51d91cf24fbea9/v8/WhenSortingLeadsToConfusion.md https://issues.chromium.org/issues/542403045 https ...
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle ...
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Use after free in WebGL in Google ...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. Improper Neutralization of Special ...
In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserved for devices. In the Linux kernel, the following ...
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user.