Kernel Bugs: Measure Chains, Not Just Crashes
A kernel crash reveals nothing about whether attackers can convert it into usable primitives or compose them into a working exploit chain.
-...

Created by Peter Felber
Timely AI security news, technical threats, governance updates, and real‑world incident analysis
Explore the latest content tracked by AI Security Pulse
A kernel crash reveals nothing about whether attackers can convert it into usable primitives or compose them into a working exploit chain.
-...
OpenAI's president claimed AGI arrival at Astra's launch, yet the company issued no formal declaration and avoided the term in official materials.
-...
Long-running AI agents create recursive attack chains where tool use and new context feed back into decisions, making the surrounding control plane...
AI threat detection delivers operational value by correlating weak signals across logs, endpoints, networks, and threat intelligence to prioritize...
A new multilingual benchmark with 11,911 questions and seven metamorphic relations evaluates 11 LLMs across 1,408 scenarios, revealing how transformations expose hidden safety vulnerabilities that standard tests miss.
Google’s Gemini 3.8 Flash targets longer, multi-step agent tasks through iterative reasoning and tool use at unchanged low pricing, while the limited-access Flash Cyber variant supplies defenders with stronger vulnerability discovery and patching.
In cybersecurity, matching the right model size to the task often beats defaulting to frontier-scale systems.
OpenAI's Astra employs recurrent depth (looped Transformers) to cut compute costs by 50-90%, but this hides reasoning steps as unintelligible...
Two new systems highlight a trend toward provable rather than asserted security automation.
Fraudsters in a $1.3M romance-investment scheme didn't just fake identities—they poisoned public data so AI summaries and search engines appeared to...
OpenAI's Astra became the first model classified at the Critical level, autonomously discovering unknown zero-days and chaining them into working...
In regulated sectors, benchmark scores measure accuracy under normal conditions while safety validation tests behavior when attackers try to break the...
Data poisoning turns training data into a supply-chain attack vector, where attackers deliberately modify, add, or remove inputs to influence AI model...
Prompt injection turned Microsoft Copilot into a data-leak and memory-poisoning vector when researchers used meta-hacking to expose an undocumented...
Specialized AI is moving vulnerability discovery from periodic scans toward always-on, targeted operations.
Frontier AI models expose decades-old vulnerabilities while handing equivalent power to attackers, forcing CISOs to simplify and consolidate security...
OpenAI’s new techniques that reduce Chain of Thought monitorability could undermine detection of deceptive behavior in frontier models. The 2025 paper...
Generic jailbreak benchmarks fail to capture real-world misuse because they target explicit harm rather than adversarial prompts framed as legitimate...