vulnerabilities
Coverage of vulnerabilities in the Nexus archive.
- Bitcoin Red Team founder turns to Chinese AI: ‘It absolutely guts me’
A Bitcoin Red Team founder has reportedly turned to Chinese AI, making the statement, 'It absolutely guts me.' Separately, the Bitcoin Red Team reported finding 1,288 critical and high-level vulnerabilities within the Bitcoin ecosystem as of Saturday.
- This Bitcoin Bridge Shut Itself Down Because AI Was Finding Bugs Too Fast
Non-custodial Bitcoin swap provider Boltz suspended swaps indefinitely as attackers discovered vulnerabilities faster than the team could address them.
- How companies could share cyber risks without exposing their secrets
Zero-knowledge proofs allow companies to prove vulnerabilities exist without revealing sensitive data like network configurations or software inventories. This cryptographic method addresses government needs to assess cyber risks while protecting proprietary information, reducing the risk of exposing attack roadmaps.
- CrowdStrike: AI is now both the weapon and the target in cyberattacks
CrowdStrike reports AI-driven cyberattacks now generate over twice as much detection noise as human-triggered incidents, with 14 million daily detection leads and 36,000 customer alerts. AI tools are both weapons and targets, enabling 89% more malicious activity and weaponizing 88% of vulnerabilities within 48 hours, forcing organizations to patch vulnerabilities in 24-48 hours.
- Apple struggles to keep pace with AI ‘bug’ hunters
Apple has limited the number of vulnerabilities security researchers can submit as it faces a surge in reports from AI 'bug hunters'. The company is struggling to manage the increased volume of submissions, which has strained its resources.
- N-day is Becoming N-Hour. Patching Faster Won't Save You.
N-day exploitation is accelerating to N-hour as attackers rapidly develop exploits from security patches. Vendors' patches reveal vulnerabilities through code diffs, enabling exploits against unpatched systems.
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two vulnerabilities in SonicWall SMA1000 were exploited in zero-day attacks for weeks, enabling threat actors to install custom malware on vulnerable VPN appliances. The flaws were recently disclosed but were used before patches were available.
- CISA urges immediate action on actively exploited Fortinet flaws
CISA has ordered government agencies to urgently patch two actively exploited vulnerabilities in Fortinet's FortiSandbox threat detection platform. The vulnerabilities are being exploited, prompting immediate action.
- Microsoft smashes Patch Tuesday record for second successive month
Microsoft has broken its Patch Tuesday record for the second consecutive month by disclosing 622 vulnerabilities, exceeding the total from the previous three months combined. Vulnerability counts have been increasing this year.
- You Don't Have to Run an Exploit to Know If You're Vulnerable
The article discusses how organizations can assess exploitability of vulnerabilities without running live exploits, particularly when systems are too critical to test. Picus introduces TTP chaining as a method to validate attack techniques an exploit relies on, offering a safer alternative to direct exploitation.
- SAP warns of critical flaws in NetWeaver and Commerce Cloud
SAP has addressed 16 vulnerabilities across multiple products in its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter.
- Ethereum Foundation Turns AI Loose on ETH Network to Find Bugs Before Hackers Do
The Ethereum Foundation is deploying AI agents to identify vulnerabilities in the ETH network. This approach shifts security efforts from merely finding bugs to verifying their validity.
- Sleepless fans in Kerala put through wringer as Argentina goes to the brink and back
The close contest highlighted Argentina’s vulnerabilities, leaving fans in Kerala in a frenzy as they celebrated their team’s narrow escape from elimination.
- Vulnerabilities Expose Private Data in Indian Government Systems
A critical vulnerability discovered by a researcher could have allowed unauthorized access to a national government portal in India, exposing private data through vulnerabilities in government systems.
- Adaptive, Agentic AI Worms Loom as Next Enterprise Threat
AI worms, described as 'viruses with wings and brains,' are capable of adapting to new environments and identifying vulnerabilities. Researchers warn these agentic threats could attack enterprises within a year.
- AI makes it easy to expose holes in Army’s unified network, official says
New AI capabilities are making it easier to exploit vulnerabilities in the Army's unified network, according to the Army’s chief data officer. The official stated these advancements are lowering the barrier for potential attackers.
- Race Against Time: Why Faster Vulnerability Alerts Matter
Attackers are exploiting vulnerabilities faster than organizations can identify and patch them. SecAlerts explains that faster vulnerability alerts can help reduce exposure and improve response times.
- Anthropic says Mythos has already found more than 10,000 vulnerabilities
Anthropic's Mythos has identified over 10,000 vulnerabilities, with Project Glasswing aiding partners in discovering high and critical severity bugs.
- Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Anthropic's Project Glasswing has identified over 10,000 high-severity vulnerabilities in critical software since its launch last month. The initiative, led by AI company Anthropic, aims to enhance cybersecurity by addressing systemic risks.
- What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)
The article highlights a common issue in security teams where end-of-quarter metrics like closed vulnerabilities and CVSS scores create a false sense of security. Leadership questions the actual safety improvements, revealing a gap in how exposure management platforms measure and communicate risk.
- ZetaChain identifies cross-chain messaging loophole as root of targeted exploit
ZetaChain's post-mortem revealed that an attacker exploited three vulnerabilities in cross-chain messaging to drain $333,868 from team wallets. The exploit was identified as a targeted attack leveraging a loophole in the system.
- Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
Anthropic’s Claude Mythos Preview, announced April 7, is a cybersecurity-focused AI system capable of identifying vulnerabilities at scale. It has sparked debate about organizations' ability to validate, prioritize, and remediate discovered vulnerabilities, highlighting gaps in readiness for large-scale vulnerability management.
- PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
PhantomCore, a pro-Ukrainian hacktivist group, has exploited vulnerabilities in TrueConf video conferencing software to breach Russian networks since September 2025, according to Positive Technologies. The attacks involved a chain of three vulnerabilities enabling remote command execution on targeted servers.
- [Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed
The article discusses how AI-powered hackers are launching automated, large-scale exploits at unprecedented speeds, drastically reducing the time available to fix vulnerabilities. It introduces the concept of the 'Collapsing Exploit Window,' emphasizing the urgent need for proactive cybersecurity measures.
- Anthropic's super-scary bug hunting model Mythos is shaping up to be a nothingburger
Anthropic's Mythos model, designed for vulnerability detection, is being withheld from public use due to fears of criminal exploitation. However, early analysis suggests the model may not pose the significant threat initially assumed.
- Serial-to-IP Devices Hide Thousands of Old and New Bugs
Serial-to-IP devices, which convert machine communication into internet protocols, are found to have numerous vulnerabilities and are increasingly targeted by attackers, according to researchers. These OT devices are critical for industrial systems but pose significant security risks.
- WARNING !!
A security specialist warns against cryptocurrencies with smart contracts and programmability, advocating for Nano XNO instead. They claim AI will increase hacking risks and suggest using advanced AI models to identify vulnerabilities in code repositories. Nano is praised for its simplicity and lack of unnecessary features.
- Claude Opus wrote a Chrome exploit for $2,283
A model called Claude Opus was used to create a Chrome exploit for $2,283, while Anthropic withheld its Mythos model due to security concerns about potential attackers exploiting software vulnerabilities.
- The Hidden Security Risks of Shadow AI in Enterprises
Employees are adopting AI tools without IT approval, leading to security risks as these tools operate outside security controls, creating blind spots in what's termed shadow AI. This mirrors the shadow IT phenomenon but introduces new vulnerabilities.