Skip to content

Topic

AI-assisted vulnerability research

Use of frontier and open-weight models to discover, triage and remediate software vulnerabilities, and the resulting shift in attacker-defender economics.

Current stories

investConfirmed2 publishers

XRP Ledger's built-in exchange carried a decade-old bug that could mint XRP past its 100 billion cap

RippleX fixed a 2015-era XRP Ledger bug that let one payment create spendable XRP beyond the token's 100 billion supply cap. Both built-in safeguards would have missed it, so the cap's record on public networks rests on RippleX's finding of no exploitation.

Reality

Evidence62
Adoption
Insufficient
Hype gap+20
Incentives60
Confidence55
buildConfirmed5 publishers

OpenSSH 10.6 turns off LZ77 compression to stop a cross-channel plaintext leak

OpenSSH 10.6, released October 6, turns off the LZ77 coder in SSH compression to block an attack that reads one channel's secrets from another. Hosts using the Compression option will get less from it, so the project suggests compressing in the application.

Perspective Coverage

5 publishers
Builder
Builder 42%
Operator
Operator 52%
Investor
Investor 6%

Reality

Evidence82
Adoption
Insufficient
Hype gap+5
Incentives20
Confidence78
buildOne report1 publisher

HFS leaks the Math.random() state that signs its admin cookies

Rejetto HFS 3.0.0 through 3.2.0 signs session cookies with a Math.random() key, and five leaked PRNG outputs let an attacker forge an admin session. Exploitation began on October 1, and version 3.2.1 restores secure key generation.

Publishers:dev.to

Reality

Evidence70
Adoption72
Hype gap0
Incentives50
Confidence65
securityConfirmed8 publishers

Exposed MikroTik SSH hands over full administrative control without authentication

CERT Polska dated successful attacks to at least September 2 and published its warning on September 5, so operators who deferred the RouterOS update have three days of configuration changes to read as well as a patch to install.

Perspective Coverage

8 publishers
Builder
Builder 19%
Operator
Operator 73%
Investor
Investor 8%

Reality

Evidence78
Adoption45
Hype gap+18
Incentives30
Confidence72
securityConfirmed5 publishers

Researchers built a WeChat worm that hijacks accounts while the phone is still ringing

Calif's WeWorm abused a memory corruption bug in WeChat's VoIP stack to take over accounts on an iPhone 17e and two Pixel 10a handsets, and Tencent blocked it server-side on 28 August without publishing an advisory or a CVE.

Perspective Coverage

6 publishers
Builder
Builder 32%
Operator
Operator 51%
Investor
Investor 17%

Reality

Evidence55
Adoption
Insufficient
Hype gap+35
Incentives60
Confidence60
scienceOne report1 publisher

Stripping refusals from Gemma tilted its bug verdicts toward yes

A researcher ran the same FreeBSD scan through base and abliterated open-weight builds and found the uncensored ones graduating three to four times as many findings, while the most aggressive one never surfaced the actual CVE.

Publishers:clearbluejar.github.io

Reality

Evidence58
Adoption14
Hype gap+14
Incentives22
Confidence46
investConfirmed3 publishers

Grayscale's ZCSH puts Zcash in brokerage accounts, and none of its ZEC is shielded

The first US spot Zcash product gives brokerage accounts price exposure to a privacy coin while holding its ZEC in transparent custody. Allocators now have to argue the asset, not the access.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 25%
Investor
Investor 48%

Reality

Evidence71
Adoption56
Hype gap+20
Incentives74
Confidence70