CVEs
Coverage of CVEs in the Nexus archive.
- Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers exploited sandbox escapes in Cursor, Codex, Gemini CLI, and Antigravity by having AI agents write files executed by trusted host tools. The vulnerabilities led to multiple CVEs, patches, and Google downgrading two Antigravity findings.
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Attackers are distributing a data-stealing trojan named ChocoPoC through fake Python proof-of-concept (PoC) repositories on GitHub. The malware targets vulnerability researchers by stealing passwords, browser cookies, and files, and granting attackers shell access to infected machines.
- Blame AI: Patch Tuesday Hits Record 206 CVEs
Patch Tuesday saw a record 206 CVEs addressed, with artificial intelligence accelerating vulnerability discovery and potentially leading to more frequent large-scale patch updates.
- Show HN: I benchmarked LLM agents on fixing real-world security vulnerabilities
A benchmark tested 5 LLM agents on fixing 20 real-world security vulnerabilities across 18 Python projects. The best solve rate was 50%, with cost differences between models (e.g., gpt-5.5 vs. gpt-5.4-mini) outweighing performance gains, likely due to training data variations.
- Cisco sings Mythos' praises - but doesn't say how many bugs the model uncovered
Cisco used Anthropic’s Claude Mythos Preview and OpenAI’s GPT 5.5-Cyber to scan 1.8 billion lines of code in eight weeks, a task that would have taken eight years manually, but did not disclose the number of vulnerabilities found. Anthropic expanded its Project Glasswing partner program to 200 organizations, and Palo Alto Networks reported 26 CVEs discovered using Mythos in a month.
- NIST narrows scope of CVE analysis to keep up with rising tide of vulnerabilities
NIST has narrowed its focus for analyzing CVEs to prioritize those in CISA's catalog, federal government software, and critical software under Executive Order 14028 due to an overwhelming increase in vulnerabilities. The change aims to stabilize the NVD program amid backlogs and funding challenges, shifting away from automatically enriching non-priority CVEs.