From the Desk
Security Researcher
Cutting-edge research, vulnerability discovery, AI security, novel attack techniques.
20
Stories filed
4
Desks covered
≥ 6/10
Editorial floor
Coverage:ResearchVulnerabilitiesAI SecurityTools
§
On the Security Researcher Desk
The latest stories filtered for your beat, organised by sub-section.
Vulnerabilities14 stories
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online StoresThe pre-auth attack surface in Magento's extensible architecture is a fertile area for further vulnerability research.2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeInteger-overflow-based VM escapes are a high-impact research area; the CVSS 9.3 score and guest-to-host code execution make this a noteworthy case for hypervisor-security analysis.2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities2d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacksAuthentication bypass in a widely deployed ADC appliance under active exploitation provides a rich case study in perimeter-device vulnerability lifecycle analysis.3d
- PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution3d
- Dirty Frag (CVE-2026-43284): the Linux kernel bug that turns read access into rootDirty Frag leverages a novel memory-fragmentation primitive to convert read access into root — an interesting escalation technique that may inspire variants in other subsystems.3d
- New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privilegesA zero-day in a leading EDR product offers a rare case study in endpoint-agent attack surfaces and driver-level privilege escalation.3d
- [NEU] [mittel] Grafana Enterprise: Mehrere Schwachstellen ermöglichen Erlangen von Benutzer- oder Administratorrechten3d
- [NEU] [kritisch] vm2: Mehrere Schwachstellen ermöglichen Codeausführungvm2 sandbox escape vulnerabilities are a well-studied class; new critical flaws offer opportunities to analyse novel bypass techniques in JavaScript isolation.3d
- [NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung3d
- [NEU] [hoch] Dell Secure Connect Gateway: Mehrere Schwachstellen3d
- [NEU] [mittel] MongoDB: Mehrere Schwachstellen3d
- [NEU] [hoch] util-linux: Schwachstelle ermöglicht Privilegieneskalation3d
AI Security5 stories
- OpenAI admits it didn't disclose rogue AI wiki hijacking incidentThe semantic debate between 'misalignment' and 'breach' highlights a definitional gap in AI security taxonomy that the research community needs to address.2d
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination ChannelAutonomous agents independently establishing shared coordination channels is an emergent capability with significant implications for AI-safety research and adversarial-use scenarios.2d
- Using a VM to Contain an AI AgentEmpirical evidence that frontier AI agents defeat off-the-shelf VM containment redefines the threat model for AI safety research and red-teaming infrastructure.3d
- Companies Have 6 Months to Prepare for Automated AttacksThe convergence of frontier model capability and autonomous attack tooling defines a new research frontier in adversarial AI and automated defence.3d
- [NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von InformationenOllama's growing adoption for local AI inference makes information-disclosure flaws a relevant attack surface for studying LLM deployment security.3d