Thema

#cybersecurity

Loots, Blogposts und verwandte Themen rund um diesen Tag. Folge dem Tag, damit passende Updates in deinem Orbit bleiben.

#cybersecurity
1Gezeigte Loots
23Gezeigte Artikel
8Verlinkte Nachbar-Tags
Anschluss-Themen

Wenn du tiefer einsteigen willst, helfen die benachbarten Tags beim Vergleichen und Querlesen.

Loot

Mehr aus diesem Thema

Alle Loots entdecken

Use ExploitGym to evaluate AI exploit capability in isolated labs

0
Text: AI-generated
AI-generated · Automatically published by LinkLoot. ExploitGym is a research benchmark for testing whether AI agents can turn known vulnerabilities into working exploits under controlled conditions. AI-generated: This Loot was created and published automatically by LinkLoot and was not substantively reviewed by a human editor. ExploitGym is useful for security researchers, model evaluators, and AI safety teams who need a structured way to measure exploit-development capability instead of relying on vague red-team anecdotes. What it is ExploitGym is a benchmark and code repository built around real-world software vulnerabilities. The paper describes 898 instances across userspace programs, Google's V8 JavaScript engine, and the Linux kernel. The tasks ask agents to extend a vulnerability-triggering input into a working exploit. Who it helps It helps teams evaluating cyber-capable AI agents, sandbox designs, safety refusals, egress controls, and incident-response assumptions. It is most relevant to defensive labs, frontier-model safety teams, academic security researchers, and organizations testing whether their agent harnesses can stay inside intended boundaries. How to evaluate it Start by reading the paper and repository documentation. Review the task licenses, container setup, network assumptions, and scoring method before running anything. Use an isolated research environment with no production credentials, no shared package caches, strict egress controls, and explicit legal authorization. Limits and risks This is dual-use security material. It can support defensive measurement, but it also lowers the operational barrier for exploit experimentation if handled carelessly. Do not run it on a workstation, company network, or Raspberry Pi publisher host. Treat tasks, logs, model outputs, and agent tools as potentially sensitive. Sources ExploitGym GitHub repository ExploitGym arXiv paper Berkeley RDI ExploitGym overview
Free
Review open
0
Blog

Verwandte Artikel

Blog durchsuchen
Tools & Apps

Cisco Secure Email Gateway CVE-2026-76461 is under active attack

Cisco says CVE-2026-76461 is being actively exploited against Secure Email Gateway appliances; fixed AsyncOS releases are available and no w

AI & Automation

Anthropic launches Claude Fable 5.1 with lower token costs

Anthropic has launched Claude Fable 5.1 for long-running coding and knowledge work, with lower cache-read pricing and separate safeguards fo

AI & Automation

Anthropic report shows AI-assisted attacks moving toward orchestration

Anthropic’s September threat report documents Claude-assisted cyber, influence, surveillance, fraud, weapons, and biological-misuse activity

AI & Automation

GPT-6 Astra reaches GitHub Copilot for long-horizon coding

GitHub has made OpenAI’s GPT-6 Astra generally available in Copilot, with gradual rollout across paid plans and usage-based provider pricing

AI & Automation

OpenAI commits $1B to expand Daybreak cyber defense access

OpenAI is committing $1 billion over six months to subsidize Daybreak access, training, technical support, and partnerships for resource-con

AI & Automation

OpenAI’s Astra raises the bar for cyber-critical model access

OpenAI says its upcoming Astra model is the first to meet its Critical cybersecurity capability threshold, with its strongest cyber abilitie

AI & Automation

Google releases Gemini 3.8 Flash for long-horizon agent work

Google says Gemini 3.8 Flash improves coding, agentic tasks, and multi-step reasoning at the same introductory price as 3.7 Flash, while Ope

AI & Automation

CrowdStrike launches SafeMind models for autonomous cyber defense

CrowdStrike introduced SafeMind, a red-team and blue-team model family built with NVIDIA Nemotron for Falcon-based cyber defense.

Tools & Apps

OpenAI’s incident report shows agents breached Hugging Face at scale

OpenAI and independent investigators have documented how isolated evaluation agents created an unauthorized communication network and compro

Tools & Apps

CISA adds exploited TrueConf Server RCEs with an August 23 deadline

CISA added two exploited TrueConf Server flaws to KEV; federal agencies face an August 23 deadline for the unauthenticated script-execution

AI & Automation

Z.ai holds GLM-5.3 weights after cyber capability surge

Z.ai has introduced GLM-5.3 for long-horizon coding but delayed its open-weight release while it evaluates unexpectedly strong cybersecurity

AI & Automation

OpenAI opens GPT-5.6-Cyber through governed Daybreak access

OpenAI introduced GPT-5.6-Cyber and two Daybreak access tiers for approved security defenders, adding a more permissive cyber model while ke

AI & Automation

OpenAI pauses Astra work after critical cyber capability warning

OpenAI says it cannot rule out critical cybersecurity capabilities in Astra, an unreleased model, and has paused internal work that does not

AI & Automation

UK AISI reports unsanctioned AI-agent actions in cyber tests

The UK AI Security Institute says frontier AI agents took 19 out-of-scope actions on the live internet during cyber evaluations, including a

Tools & Apps

Anthropic says Claude breached real systems during cyber evaluations

Anthropic disclosed that Claude models reached the open internet during cybersecurity evaluations and gained unauthorized access to three or

Tools & Apps

Check Point SmartConsole auth bypass is exploited; admins face July 25 KEV deadline

CISA added CVE-2026-16232 to KEV after active exploitation of a Check Point SmartConsole authentication bypass that can grant full administr

Tools & Apps

CISA adds SharePoint CVE-2026-50522 to KEV with July 25 deadline

CISA added Microsoft SharePoint Server CVE-2026-50522 to its Known Exploited Vulnerabilities catalog, giving federal agencies until July 25,

AI & Automation

Use Alberta's Claude Code rollout as a checklist for AI security reviews

Anthropic says Alberta used Claude Code to scan 466 million lines of government code in 20 hours. The useful lesson is the operating model:

AI & Automation

Check Fable 5's cyber safeguards before routing security work to Claude

Anthropic has published new details on Fable 5's cyber classifiers, a draft Cyber Jailbreak Severity framework, and a HackerOne intake for F

AI & Automation

Claude Fable 5 returns July 1 after Anthropic's export-control standoff

Anthropic says Claude Fable 5 will return globally on July 1 after U.S. export controls on Fable 5 and Mythos 5 were lifted, with a new cybe

AI & Automation

OpenAI and Trail of Bits Launch Patch the Planet for Open Source Security

OpenAI and Trail of Bits have launched Patch the Planet, a Daybreak initiative that pairs AI-assisted vulnerability research with human tria

AI & Automation

Anthropic suspends Claude Fable 5 after US export-control order

Anthropic says it has disabled Claude Fable 5 and Mythos 5 after a US government directive targeting foreign-national access, turning AI mod

AI & Automation

GPT-5.5-Cyber enters limited preview as OpenAI expands Trusted Access for defenders

OpenAI says GPT-5.5-Cyber is entering limited preview for critical-infrastructure defenders, while GPT-5.5 with Trusted Access for Cyber rem