Teen's Auth Flaw Opened Titan's Data Vault
A 16-year-old researcher bypassed Microsoft's Titan analytics by exploiting an unverified JWT and was paid a $5,000 bounty.
30 results for “research”
A 16-year-old researcher bypassed Microsoft's Titan analytics by exploiting an unverified JWT and was paid a $5,000 bounty.
Researchers debate whether AI's catastrophic risks are real threats or marketing, from nuclear war to bioweapons and runaway models.
Researchers show how a compromised Entra admin account can turn a trusted external MFA provider into a credential-stealing prompt.
Researchers say a package posing as an authorized Twilio bug-bounty probe went through 11 versions before trying to exfiltrate API credentials.
Cisco Talos says it has identified CLOSEDQUORUM, a proof-of-concept implant that uses an LLM panel to drive an attack without a live operator.
SpyCloud research finds infostealer malware has harvested credentials tied to 1,787 U.S. water and wastewater organizations, some reaching operational networks.
A researcher's new Windows Defender zero-day prevents signature and platform updates, the latest in a string of exploits tied to a dispute with Microsoft.
Trellix researchers detail a spear-phishing chain abusing mshta.exe and a spoofed document shortcut to deliver the ReverseRAT trojan to academic institutions.
Researcher says a local attacker can redirect Meta's Muse dictation traffic through an undocumented app setting, with no special privileges.
AI & MLA conference panel on world models revealed that leading labs avoid discussing products or timelines, citing competitive risk.
Researchers chained an ImageMagick flaw with an OpenAI sign-in issue to reach internal code, earning a bounty.
A researcher published working local-root exploits for four Linux kernel bugs fixed weeks earlier, flagging a patching race for older systems.
New research finding watermarking alters model behavior, including refusal of harmful requests and tool calling.
A new WordPress core flaw lets a crafted link silently install a theme, and researchers chained it to full code execution.
A zero-click remote code execution flaw in popular AI coding agents could let attackers run malicious code without developer interaction, researchers warn.
Researchers say a swarm of OpenAI agents flooded RubyGems with more than 2,000 malicious packages, forcing a four-day signup freeze.
New Pistachio research argues click rate alone misleads, and that credential leaks and reporting matter just as much.
Security researcher finds a hardcoded admin account in a Temu-bought Wi-Fi extender, giving remote attackers full control.
GitLab patches a maximum-severity path traversal flaw and a critical EE deserialization bug as researchers report in-the-wild probing within hours.
A researcher says he left Anthropic over concerns it and OpenAI prioritize competitive advantage over safety in AI development.
Noma Labs research describes an authorization design flaw that lets unauthenticated input trigger privileged AI workflow actions.
A Wiz Research scan found 294 exposed LiteLLM gateways accepted the example admin key sk-1234, granting access to stored provider credentials.
Paul Christiano, who pioneered a key training technique, joins OpenAI's foundation board and its safety committee, citing near-term loss-of-control risk.
Fusionality, founded by two fusion researchers, raises $3.7M to standardize reactor control systems.
A complex JavaScript-based malware that can replay stolen browser sessions to breach Google accounts keeps evolving, researchers warn.
New research maps North Korea's Lazarus umbrella into six distinct cyber clusters with specialized roles.
Researchers say a swarm of OpenAI agents used a dormant German wiki as a message board in May, months before the Hugging Face incident.
The researcher known as Nightmare Eclipse has released FalconFlank, a privilege escalation exploit targeting CrowdStrike Falcon via a Windows Office macro feature.
Forescout researchers used AI to port RCE exploits to PLCs, but high cost and effort still deter criminals.
Hackers exploit Faronics Deploy to enroll victims and install ScreenConnect, researchers report.