<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Bugflation</title><description>Public evidence that AI-assisted systems are changing vulnerability discovery economics.</description><link>https://bugflation.com/</link><language>en-us</language><item><title>[Finding] Anthropic CVD dashboard reveals fixed Mythos Preview open-source findings</title><link>https://bugflation.com/findings/anthropic-cvd-may-2026-mythos-oss-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/anthropic-cvd-may-2026-mythos-oss-cluster/</guid><description>Anthropic&apos;s Project Glasswing CVD dashboard revealed 17 fixed, CVE/GHSA-backed open-source entries attributed to Claude Mythos Preview, including Nomad, Temporal, Mastodon, FreeRDP, jq, MapServer, wolfSSL, Gitoxide, Ghost, Craft CMS, and other projects. - Project Glasswing CVD cluster: path traversal, broken access control, SSRF, heap overflow, SQL injection, RCE, and privilege escalation, severity critical, credited system Claude Mythos Preview, attribution direct.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>claude-mythos</category><category>direct</category></item><item><title>[Finding] DepthFirst autonomously finds NGINX Rift and three companion CVEs</title><link>https://bugflation.com/findings/cve-2026-42945-nginx-rift-depthfirst/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-42945-nginx-rift-depthfirst/</guid><description>DepthFirst says its autonomous low-level analysis platform found four confirmed NGINX memory-corruption issues, led by CVE-2026-42945, the critical NGINX Rift rewrite-module heap overflow. - NGINX memory-corruption cluster led by rewrite-module heap overflow RCE, severity critical, credited system DepthFirst, attribution self-reported.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>depthfirst</category><category>self-reported</category></item><item><title>[Finding] Fragnesia: V12-assisted Linux kernel page-cache LPE CVE-2026-46300</title><link>https://bugflation.com/findings/cve-2026-46300-fragnesia-v12-linux-kernel/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-46300-fragnesia-v12-linux-kernel/</guid><description>V12&apos;s public PoC and write-up say Fragnesia, CVE-2026-46300, was discovered with V12 by William Bowling and the V12 team; distro trackers and kernel patch mail corroborate the Linux XFRM ESP-in-TCP local-root vulnerability. - Shared page-fragment marker loss leading to page-cache corruption and local privilege escalation, severity high, credited system V12, attribution direct.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>v12</category><category>direct</category></item><item><title>[Finding] Palo Alto Networks reports 26-CVE frontier-AI scan wave</title><link>https://bugflation.com/findings/palo-alto-frontier-ai-may-2026-cve-wave/</link><guid isPermaLink="true">https://bugflation.com/findings/palo-alto-frontier-ai-may-2026-cve-wave/</guid><description>Palo Alto Networks says its May 2026 Patch Wednesday wave covered 26 CVEs representing 75 issues after scanning more than 130 products with frontier AI models, including Anthropic Mythos, Claude Opus 4.7, and OpenAI GPT-5.5-Cyber. - Vendor-scale frontier-AI vulnerability-discovery wave across PAN-OS, GlobalProtect, Prisma, Cortex, WildFire, Browser, and related products, severity high, credited system Palo Alto frontier AI scan, attribution self-reported.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>palo-alto-frontier-ai-scan</category><category>self-reported</category></item><item><title>[Finding] Microsoft MDASH publishes 16 Windows networking and authentication CVEs</title><link>https://bugflation.com/findings/microsoft-mdash-may-2026-windows-cve-cohort/</link><guid isPermaLink="true">https://bugflation.com/findings/microsoft-mdash-may-2026-windows-cve-cohort/</guid><description>Microsoft says its multi-model agentic scanning harness, codename MDASH, helped researchers find 16 CVEs across Windows networking and authentication code, including four Critical remote code execution flaws. - Windows network-stack and authentication vulnerability-discovery cluster, severity critical, credited system Microsoft MDASH, attribution direct.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>microsoft-mdash</category><category>direct</category></item><item><title>DirtyFrag and Copy Fail2 Show the Page-Cache Bug Class Is Not Done</title><link>https://bugflation.com/articles/dirtyfrag-copyfail2-page-cache-bug-class/</link><guid isPermaLink="true">https://bugflation.com/articles/dirtyfrag-copyfail2-page-cache-bug-class/</guid><description>DirtyFrag and Copy Fail2 are not new AI-attributed findings, but they are important CopyFail-adjacent evidence: Linux still has dangerous seams where zero-copy networking, page-cache provenance, and in-place crypto meet.</description><pubDate>Fri, 08 May 2026 06:45:00 GMT</pubDate><category>linux</category><category>copyfail</category><category>dirtyfrag</category><category>page-cache</category><category>analysis</category><author>Mounir Idrassi</author></item><item><title>The Public Record Is Thin, but Real</title><link>https://bugflation.com/articles/public-record-is-thin-but-real/</link><guid isPermaLink="true">https://bugflation.com/articles/public-record-is-thin-but-real/</guid><description>The AI vulnerability-discovery record is still small, but direct credits now span browsers, kernels, bootloaders, crypto libraries, and OSS tooling.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><category>methodology</category><category>evidence</category><author>Bugflation Editorial</author></item><item><title>[Finding] Bynario AI assists Linux CAN raw socket UAF fix</title><link>https://bugflation.com/findings/cve-2026-31532-linux-can-bynario/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-31532-linux-can-bynario/</guid><description>Bynario says its LLM-driven pipeline discovered, validated, and patched CVE-2026-31532, a Linux kernel CAN raw socket use-after-free; the upstream Linux commit includes Assisted-by: Bynario AI. - RCU teardown race causing use-after-free of per-CPU CAN raw socket state, severity high, credited system BynarIO AI, attribution direct.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>bynario-ai</category><category>direct</category></item><item><title>[Finding] ZeroPath finds Apache NiFi Execute Code permission bypass CVE-2026-39816</title><link>https://bugflation.com/findings/cve-2026-39816-apache-nifi-zeropath/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-39816-apache-nifi-zeropath/</guid><description>ZeroPath Research disclosed an Apache NiFi authorization flaw where users without EXECUTE_CODE can run code through TinkerpopClientService when optional graph extensions are installed. - Authorization bypass leading to server-side code execution, severity high, credited system ZeroPath AI SAST, attribution self-reported.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>self-reported</category></item><item><title>CopyFail Is the Bugflation Moment</title><link>https://bugflation.com/articles/copyfail-is-the-bugflation-moment/</link><guid isPermaLink="true">https://bugflation.com/articles/copyfail-is-the-bugflation-moment/</guid><description>CVE-2026-31431 shows the bugflation pattern: expert framing plus AI-assisted subsystem review made a kernel root bug cheap to surface.</description><pubDate>Mon, 04 May 2026 12:00:00 GMT</pubDate><category>copyfail</category><category>linux</category><category>xint-code</category><category>thesis</category><author>Mounir Idrassi</author></item><item><title>Introducing Bugflation</title><link>https://bugflation.com/articles/introducing-bugflation/</link><guid isPermaLink="true">https://bugflation.com/articles/introducing-bugflation/</guid><description>Bugflation names the gap between AI-accelerated vulnerability discovery and the slower systems that validate, patch, and deploy fixes.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>editorial</category><category>thesis</category><author>Mounir Idrassi</author></item><item><title>Second-Pass Audit: What Changed in the Ledger</title><link>https://bugflation.com/articles/second-pass-audit-what-changed/</link><guid isPermaLink="true">https://bugflation.com/articles/second-pass-audit-what-changed/</guid><description>The launch audit added AI-attributed disclosures from Security Copilot, Claude, OpenAI Codex Security, AISLE, OSS-Fuzz AI, and Calif.io.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>audit</category><category>evidence</category><author>Bugflation Editorial</author></item><item><title>[Finding] Striga says its Apache httpd scan surfaced CVE-2026-23918</title><link>https://bugflation.com/findings/cve-2026-23918-apache-httpd-striga/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-23918-apache-httpd-striga/</guid><description>Striga says an open-weights model scan costing under $100 surfaced the Apache HTTP Server 2.4.66 mod_http2 double-free behind CVE-2026-23918; Apache credits Bartlomiej Dmitruk, striga.ai, and Stanislaw Strzalkowski, isec.pl, as finders. - HTTP/2 double free with possible remote code execution, severity high, credited system Striga AI, attribution self-reported.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>striga-ai</category><category>self-reported</category></item><item><title>Patch Capacity Is the Bottleneck</title><link>https://bugflation.com/articles/patch-capacity-is-the-bottleneck/</link><guid isPermaLink="true">https://bugflation.com/articles/patch-capacity-is-the-bottleneck/</guid><description>If AI makes discovery cheaper, the scarce resource moves downstream: triage, reproduction, patch review, release engineering, and deployment.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate><category>operations</category><category>defense</category><author>Bugflation Editorial</author></item><item><title>From Big Sleep to XBOW: Two Different Signals</title><link>https://bugflation.com/articles/from-big-sleep-to-xbow/</link><guid isPermaLink="true">https://bugflation.com/articles/from-big-sleep-to-xbow/</guid><description>Big Sleep and XBOW point to different parts of the AI security stack: source-aware vulnerability research and autonomous black-box testing.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>big-sleep</category><category>xbow</category><category>analysis</category><author>Bugflation Editorial</author></item><item><title>[Finding] Bynario AI assists Linux FUSE page-cache overflow fix</title><link>https://bugflation.com/findings/cve-2026-31694-linux-fuse-bynario/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-31694-linux-fuse-bynario/</guid><description>The Linux fix for CVE-2026-31694, a FUSE readdir page-cache overflow, includes Assisted-by: Bynario AI; Bynario says its LLM-driven pipeline found and validated the FUSE bug, while the upstream commit also carries separate reporter credits. - Oversized FUSE dirent copied into a single page-cache page, severity high, credited system BynarIO AI, attribution direct.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>bynario-ai</category><category>direct</category></item><item><title>[Finding] AISLE finds FreeBSD dhclient root RCE and two companion core CVEs</title><link>https://bugflation.com/findings/aisle-freebsd-april-2026-dhclient-libnv-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/aisle-freebsd-april-2026-dhclient-libnv-cluster/</guid><description>FreeBSD&apos;s April 29, 2026 advisories credit Joshua Rogers of AISLE Research Team for CVE-2026-42511, a local-network-to-root dhclient RCE, plus a second dhclient heap overflow and a libnv stack overflow. - DHCP client command injection, heap overflow, and libnv stack overflow, severity high, credited system AISLE, attribution direct.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>aisle</category><category>direct</category></item><item><title>[Finding] CopyFail: Linux kernel page-cache write to root found with Xint Code</title><link>https://bugflation.com/findings/cve-2026-31431-copyfail-linux-kernel/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-31431-copyfail-linux-kernel/</guid><description>CVE-2026-31431 is a Linux kernel AF_ALG/authencesn logic bug that gives an unprivileged local user a controlled 4-byte page-cache write and a reliable path to root on affected systems. - Incorrect resource transfer -&gt; page-cache corruption -&gt; local privilege escalation, severity high, credited system Xint Code, attribution direct.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>xint-code</category><category>direct</category></item><item><title>[Finding] Xint public tracker adds seven CVE-backed findings beyond CopyFail</title><link>https://bugflation.com/findings/xint-code-public-tracker-cve-backed-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/xint-code-public-tracker-cve-backed-cluster/</guid><description>Theori&apos;s Xint public bug tracker lists 50 Xint tracker findings as of May 5, 2026; seven non-CopyFail entries have CVE IDs across CPython, CUPS, NGINX, mruby, MariaDB, and PostgreSQL. - Memory-safety and parser vulnerabilities across open-source server and runtime projects, severity critical, credited system Xint Code, attribution self-reported.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>xint-code</category><category>self-reported</category></item><item><title>[Finding] ZeroPath finds ProFTPD mod_sql CVE-2026-42167</title><link>https://bugflation.com/findings/cve-2026-42167-proftpd-zeropath/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-42167-proftpd-zeropath/</guid><description>ZeroPath Research disclosed a ProFTPD mod_sql SQL injection that can lead to authentication bypass, privilege escalation, credential exfiltration, or RCE depending on configuration; ProFTPD fixed it in 1.3.9a. - SQL injection in FTP SQL logging and authentication paths, severity high, credited system ZeroPath AI SAST, attribution self-reported.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>self-reported</category></item><item><title>[Finding] AISLE autonomous analyzer finds a 20-CVE OpenSSL run</title><link>https://bugflation.com/findings/aisle-openssl-2025-2026-cve-run/</link><guid isPermaLink="true">https://bugflation.com/findings/aisle-openssl-2025-2026-cve-run/</guid><description>AISLE reports 20 OpenSSL CVEs across three coordinated releases, including all 12 January 2026 OpenSSL CVEs and five of seven April 2026 CVEs. - Cryptographic-library vulnerability cluster, severity high, credited system AISLE, attribution direct.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>aisle</category><category>direct</category></item><item><title>[Finding] FreeBSD April kernel follow-ups credited to Nicholas Carlini using Claude</title><link>https://bugflation.com/findings/freebsd-april-2026-claude-followups/</link><guid isPermaLink="true">https://bugflation.com/findings/freebsd-april-2026-claude-followups/</guid><description>FreeBSD-SA-26:10.tty and FreeBSD-SA-26:11.amd64 credit Nicholas Carlini using Claude, Anthropic for two additional kernel security advisories after CVE-2026-4747. - Kernel use-after-free and memory-protection logic flaws, severity high, credited system Claude / Anthropic Research, attribution direct.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category></item><item><title>[Finding] Firefox 150 ships fixes for 271 Mythos-identified vulnerabilities</title><link>https://bugflation.com/findings/mozilla-firefox-150-mythos-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/mozilla-firefox-150-mythos-cluster/</guid><description>Mozilla says Firefox 150 includes fixes for 271 vulnerabilities identified during an initial Claude Mythos Preview evaluation; public CVE advisories include direct Claude credit on specific entries. - Browser vulnerability cluster, severity high, credited system Claude Mythos Preview, attribution direct.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-mythos</category><category>direct</category></item><item><title>[Finding] ZeroPath discloses two critical Spinnaker RCE CVEs</title><link>https://bugflation.com/findings/zeropath-spinnaker-rce-cve-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/zeropath-spinnaker-rce-cve-2026-cluster/</guid><description>ZeroPath Research says it found two critical Spinnaker RCEs, CVE-2026-32604 and CVE-2026-32613, in Clouddriver and Echo; GitHub advisories rate both 9.9 critical and Spinnaker shipped fixes. - Command injection and Spring Expression Language code injection in deployment services, severity critical, credited system ZeroPath AI SAST, attribution self-reported.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>zeropath-ai-sast</category><category>self-reported</category></item><item><title>[Finding] Calif.io MADBugs credits Claude on NGINX and wolfSSL findings</title><link>https://bugflation.com/findings/califio-claude-nginx-wolfssl-madbugs/</link><guid isPermaLink="true">https://bugflation.com/findings/califio-claude-nginx-wolfssl-madbugs/</guid><description>Calif.io&apos;s MADBugs work with Claude and Anthropic Research produced a high-severity NGINX DAV issue and a wolfSSL release cluster credited to Calif.io in collaboration with Claude and Anthropic Research. - Web server and cryptographic-library vulnerability cluster, severity high, credited system Claude / Anthropic Research, attribution direct.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category></item><item><title>[Finding] FreeBSD NFS remote kernel RCE identified and exploited by Claude Mythos Preview</title><link>https://bugflation.com/findings/cve-2026-4747-freebsd-mythos-nfs-rce/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-4747-freebsd-mythos-nfs-rce/</guid><description>CVE-2026-4747 is a 17-year-old FreeBSD RPCSEC_GSS/NFS kernel RCE that Anthropic says Claude Mythos Preview fully autonomously identified and exploited. - Remote kernel memory corruption -&gt; root code execution, severity critical, credited system Claude Mythos Preview, attribution direct.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>claude-mythos</category><category>direct</category></item><item><title>[Finding] Claude-assisted review finds Apache ActiveMQ Jolokia RCE CVE-2026-34197</title><link>https://bugflation.com/findings/cve-2026-34197-activemq-claude/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-34197-activemq-claude/</guid><description>Horizon3.ai says Claude took the first pass on the source-code review that led to CVE-2026-34197, an Apache ActiveMQ Jolokia/JMX code-execution issue later accepted by Apache and added to CISA KEV. - Jolokia/JMX code execution through network connector configuration, severity high, credited system Claude / Anthropic Research, attribution direct.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category></item><item><title>[Finding] Mozilla Firefox 148 and 149 advisories credit Claude-assisted research</title><link>https://bugflation.com/findings/claude-firefox-148-149-cve-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/claude-firefox-148-149-cve-cluster/</guid><description>Anthropic says Claude Opus 4.6 found 22 Firefox vulnerabilities in two weeks; Mozilla advisories for Firefox 148 and 149 publicly credit researchers using Claude from Anthropic across 28 CVEs. - Browser memory-safety and sandbox-relevant vulnerability cluster, severity high, credited system Claude / Anthropic Research, attribution direct.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category></item><item><title>[Finding] Microsoft Bing Images OS command injection credited by XBOW</title><link>https://bugflation.com/findings/cve-2026-32191-bing-images-command-injection/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-32191-bing-images-command-injection/</guid><description>CVE-2026-32191 is a critical Bing Images remote-code-execution issue that XBOW lists among autonomous findings in Microsoft software. - OS command injection -&gt; remote code execution, severity critical, credited system XBOW, attribution self-reported.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>xbow</category><category>self-reported</category></item><item><title>[Finding] Microsoft Bing Images command injection credited by XBOW</title><link>https://bugflation.com/findings/cve-2026-32194-bing-images-command-injection/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-32194-bing-images-command-injection/</guid><description>CVE-2026-32194 is a critical Bing Images command-injection RCE that XBOW says was found by its autonomous offensive-security system. - Command injection -&gt; remote code execution, severity critical, credited system XBOW, attribution self-reported.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>xbow</category><category>self-reported</category></item><item><title>[Finding] OpenAI Codex Security publishes OSS CVE examples</title><link>https://bugflation.com/findings/openai-codex-security-oss-cve-examples/</link><guid isPermaLink="true">https://bugflation.com/findings/openai-codex-security-oss-cve-examples/</guid><description>OpenAI says Codex Security, formerly Aardvark, has produced 14 assigned CVEs in open-source projects and lists examples across GnuTLS, Gogs, Thorium, and GnuPG. - Open-source vulnerability discovery and validation cluster, severity high, credited system OpenAI Aardvark / Codex Security, attribution direct.</description><pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-aardvark</category><category>direct</category></item><item><title>[Finding] Microsoft Devices Pricing Program critical RCE credited by XBOW</title><link>https://bugflation.com/findings/cve-2026-21536-microsoft-devices-pricing/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-21536-microsoft-devices-pricing/</guid><description>XBOW says it was credited for CVE-2026-21536, a critical Microsoft Devices Pricing Program remote-code-execution vulnerability with a 9.8 CVSS v3.1 score. - Remote code execution, severity critical, credited system XBOW, attribution self-reported.</description><pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>xbow</category><category>self-reported</category></item><item><title>[Finding] Apple WebKit 26.2 follow-up issues credited to Google Big Sleep</title><link>https://bugflation.com/findings/apple-webkit-26-2-bigsleep-followups/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-webkit-26-2-bigsleep-followups/</guid><description>Apple&apos;s iOS 26.2 and iPadOS 26.2 security content credits Google Big Sleep on additional WebKit issues, including CVE-2025-43535 and CVE-2025-46299. - WebKit memory handling / internal-state disclosure, severity medium, credited system Google Big Sleep, attribution direct.</description><pubDate>Fri, 09 Jan 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>google-big-sleep</category><category>direct</category></item><item><title>[Finding] ZeroPath AI SAST reports seven FFmpeg memory-safety fixes</title><link>https://bugflation.com/findings/zeropath-ffmpeg-seven-memory-safety-fixes/</link><guid isPermaLink="true">https://bugflation.com/findings/zeropath-ffmpeg-seven-memory-safety-fixes/</guid><description>ZeroPath says its AI-assisted SAST reported seven FFmpeg memory-safety and protocol-logic bugs, including buffer overflows, invalid frees, and underflow-driven memory disclosure; the public post links to upstream FFmpeg patches. - Memory-safety and protocol logic vulnerability cluster, severity high, credited system ZeroPath AI SAST, attribution self-reported.</description><pubDate>Tue, 02 Dec 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>self-reported</category></item><item><title>[Finding] ZeroPath AI Security Engineer credited on sudo exec_mailer fix</title><link>https://bugflation.com/findings/zeropath-sudo-exec-mailer-crackarmor/</link><guid isPermaLink="true">https://bugflation.com/findings/zeropath-sudo-exec-mailer-crackarmor/</guid><description>The sudo project credited the ZeroPath AI Security Engineer for an exec_mailer fix that made privilege-drop failures fatal and dropped group privileges; Qualys later documented the same sudo behavior as part of its CrackArmor AppArmor + Sudo + Postfix root chain. - Incomplete privilege drop in sudo mailer execution, severity high, credited system ZeroPath AI SAST, attribution direct.</description><pubDate>Sat, 08 Nov 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>direct</category></item><item><title>[Finding] Apple WebKit 26.1 security cluster credited to Google Big Sleep</title><link>https://bugflation.com/findings/apple-webkit-26-1-bigsleep-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-webkit-26-1-bigsleep-cluster/</guid><description>Apple&apos;s Safari 26.1 security content credits Google Big Sleep for five WebKit CVEs spanning buffer overflow, state handling, memory corruption, and use-after-free issues. - WebKit memory-safety cluster, severity high, credited system Google Big Sleep, attribution direct.</description><pubDate>Mon, 03 Nov 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>google-big-sleep</category><category>direct</category></item><item><title>[Finding] Apple credits BynarIO AI on Model I/O CVE-2025-43377</title><link>https://bugflation.com/findings/cve-2025-43377-apple-modelio-bynario/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-43377-apple-modelio-bynario/</guid><description>Apple&apos;s macOS Sequoia 15.7.2 security content credits BynarIO AI for CVE-2025-43377, a Model I/O out-of-bounds read fixed with improved bounds checking. - Out-of-bounds read in Model I/O media parsing, severity medium, credited system BynarIO AI, attribution direct.</description><pubDate>Mon, 03 Nov 2025 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>bynario-ai</category><category>direct</category></item><item><title>[Finding] ZeroPath scanner finds better-auth API key takeover CVE-2025-61928</title><link>https://bugflation.com/findings/cve-2025-61928-better-auth-zeropath/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-61928-better-auth-zeropath/</guid><description>ZeroPath says its scanner found an authentication-bypass flaw in better-auth&apos;s API keys plugin that allowed unauthenticated attackers to mint or update API keys for arbitrary users. - Authentication bypass in API key creation and update routes, severity high, credited system ZeroPath AI SAST, attribution self-reported.</description><pubDate>Sun, 19 Oct 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>self-reported</category></item><item><title>[Finding] Chrome ANGLE use-after-free reported by Google Big Sleep</title><link>https://bugflation.com/findings/cve-2025-9478-chrome-angle-bigsleep/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-9478-chrome-angle-bigsleep/</guid><description>CVE-2025-9478 is a critical Chrome ANGLE use-after-free reported by Google Big Sleep and fixed in Chrome 139.0.7258.154/.155. - Use-after-free -&gt; heap corruption, severity critical, credited system Google Big Sleep, attribution direct.</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>google-big-sleep</category><category>direct</category></item><item><title>[Finding] Chrome V8 out-of-bounds write reported by Google Big Sleep</title><link>https://bugflation.com/findings/cve-2025-9132-chrome-v8-oob-write/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-9132-chrome-v8-oob-write/</guid><description>Chrome 139 fixed CVE-2025-9132, a high-severity V8 out-of-bounds write reported by Google Big Sleep. - Out-of-bounds write -&gt; heap corruption, severity high, credited system Google Big Sleep, attribution direct.</description><pubDate>Tue, 19 Aug 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>google-big-sleep</category><category>direct</category></item><item><title>[Finding] SQLite aggregate-term memory corruption found by Big Sleep</title><link>https://bugflation.com/findings/cve-2025-6965-sqlite-aggregate-terms/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-6965-sqlite-aggregate-terms/</guid><description>CVE-2025-6965 affected SQLite before 3.50.2 and was publicly described by Google as a Big Sleep finding that helped cut off imminent exploitation. - Aggregate-term accounting -&gt; memory corruption, severity high, credited system Google Big Sleep, attribution direct.</description><pubDate>Tue, 15 Jul 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>google-big-sleep</category><category>direct</category></item><item><title>[Finding] Microsoft Security Copilot accelerates GRUB2, U-Boot, and Barebox findings</title><link>https://bugflation.com/findings/microsoft-security-copilot-bootloader-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/microsoft-security-copilot-bootloader-cluster/</guid><description>Microsoft says Security Copilot helped uncover 20 bootloader CVEs spanning GRUB2, U-Boot, and Barebox, including Secure Boot bypass-relevant GRUB2 memory-corruption flaws. - Bootloader memory corruption and Secure Boot bypass-relevant flaws, severity high, credited system Microsoft Security Copilot, attribution direct.</description><pubDate>Mon, 31 Mar 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>microsoft-security-copilot</category><category>direct</category></item><item><title>[Finding] Google OSS-Fuzz AI finds OpenSSL CVE-2024-9143</title><link>https://bugflation.com/findings/google-oss-fuzz-ai-openssl-cve-2024-9143/</link><guid isPermaLink="true">https://bugflation.com/findings/google-oss-fuzz-ai-openssl-cve-2024-9143/</guid><description>Google says its LLM-generated and enhanced OSS-Fuzz targets found 26 new vulnerabilities, highlighted by CVE-2024-9143 in OpenSSL. - AI-generated fuzz target vulnerability discovery, severity medium, credited system Google OSS-Fuzz AI, attribution direct.</description><pubDate>Wed, 20 Nov 2024 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>google-oss-fuzz-ai</category><category>direct</category></item><item><title>[Finding] Big Sleep finds an exploitable SQLite stack buffer underflow before release</title><link>https://bugflation.com/findings/google-bigsleep-sqlite-stack-underflow/</link><guid isPermaLink="true">https://bugflation.com/findings/google-bigsleep-sqlite-stack-underflow/</guid><description>Google Project Zero and DeepMind reported Big Sleep&apos;s first public real-world finding: an exploitable SQLite memory-safety issue fixed before reaching an official release. - Stack buffer underflow, severity high, credited system Google Big Sleep, attribution direct.</description><pubDate>Fri, 01 Nov 2024 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>google-big-sleep</category><category>direct</category></item></channel></rss>