AI's Offense Outpaces Its Defense
AI can find zero-days but still can't reliably write secure code, studies show.
30 results for “code”
AI can find zero-days but still can't reliably write secure code, studies show.
UNISOC modem flaw lets attackers escalate code execution to kernel level via video calls.
A major outage hit Claude.ai, Claude Code, and Claude Cowork on August 16, with services restored by evening.
Anthropic details how Claude’s watermarking works, addressing evade, edit, and code concerns.
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.
A Cursor bug let repositories run commands pre-trust, even with the sandbox enabled.
SAP's August 2026 patch batch addresses 28 flaws, including a 10/10 severity bug in Commerce Cloud that could allow attackers to bypass authentication and execute code.
Chainguard webinar examines how security teams can manage risk when AI speeds up code production by 10-50x.
A malicious VS Code extension pack targets developers, exfiltrating wallets, credentials, and API keys via Telegram.
UK pub chain tells customers to turn off cameras on Meta-style glasses, citing privacy and a breach of common code.
Anthropic makes auto mode the default in Claude Code from August 14, claiming its classifier is safer than human approval.
A critical command injection vulnerability in the MSI RadiX AXE6600 router allows remote attackers to execute arbitrary code and gain root access.
A critical buffer overflow vulnerability in the D-Link DWR-M961 allows remote attackers to execute arbitrary code or crash the device.
A critical vulnerability in CodeIgniter 4 allows attackers to bypass file validation, potentially leading to remote code execution on affected servers.
A critical authorization bypass in the Paperclip platform allowed attackers to execute arbitrary code with server-level permissions.
An unauthenticated remote code execution vulnerability in Nuxt DevTools allows attackers to run arbitrary commands on developer machines via the HMR port.
A critical remote code execution vulnerability in Flowise allows low-privileged attackers to gain root access on vulnerable servers via CSV Agent code injection.
A critical remote code execution vulnerability in Flowise's CSVAgent allows attackers to bypass python code filters using pandas read_pickle deserialization.
A critical PHP object injection vulnerability in MaxSite CMS allows unauthenticated attackers to execute arbitrary code via a malicious cookie.
A critical remote code execution vulnerability in MaxSite CMS allows unauthenticated attackers to inject malicious PHP code into configuration files.
A Unicode homoglyph bypass in Flowise allows attackers to execute arbitrary code on host systems by tricking the Python code validation engine.
A code injection vulnerability in IBM Langflow has been added to CISA's catalog, requiring rapid remediation for federal agencies.
A missing authentication vulnerability in OpenCode Studio versions prior to 2.4.4 allows unauthenticated attackers to steal files and delete user videos.
An unauthenticated remote code execution vulnerability in Kotaemon allows attackers to run arbitrary system commands by exploiting insecure deserialization.
Puwell IP cameras running firmware versions 2.x through 4.x are vulnerable to unauthenticated remote code execution via a flaw in the DebugShell interface.
A critical unrestricted file upload vulnerability in Bilin Software's HUMANIST Digital Human Resources allows remote attackers to execute code.
A critical remote command injection vulnerability in GL.iNet GL-MT3000 routers allows unauthenticated attackers to execute arbitrary code on affected devices.
A critical SQL injection vulnerability in Adobe Campaign Classic allows low-privileged attackers to execute arbitrary code without user interaction.
A critical template engine vulnerability in Adobe Campaign Classic allows for unauthenticated remote code execution with a maximum CVSS score of 10.
A critical vulnerability in Adobe Campaign Classic allows low-privileged attackers to execute arbitrary code without requiring user interaction.