<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Bugflation</title><description>Public evidence that AI-assisted systems are changing vulnerability discovery economics.</description><link>https://bugflation.com/</link><language>en-us</language><item><title>August 2026 Source Audit: The Ledger Passes 500 Public CVEs</title><link>https://bugflation.com/articles/august-2026-source-audit/</link><guid isPermaLink="true">https://bugflation.com/articles/august-2026-source-audit/</guid><description>A primary-source reconciliation adds 134 unique CVE IDs, eight accepted no-CVE campaigns, eleven system profiles, and explicit caveats for unresolved tracker evidence.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><category>audit</category><category>evidence</category><category>methodology</category><author>Bugflation Editorial</author></item><item><title>[Finding] AISLE&apos;s late-July and August stream adds forty-five public CVE IDs</title><link>https://bugflation.com/findings/aisle-late-july-august-2026-45-cve-wave/</link><guid isPermaLink="true">https://bugflation.com/findings/aisle-late-july-august-2026-45-cve-wave/</guid><description>AISLE&apos;s public discovery registry adds forty-five exact CVE IDs across twenty-one projects after Bugflation&apos;s July audit cutoff. - Memory corruption, authentication and authorization, injection, information disclosure, and denial-of-service flaws, severity critical, credited systems AISLE (self-reported).</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category></item><item><title>[Finding] Chrome directly credits Codex Security on three new high-severity CVEs</title><link>https://bugflation.com/findings/chrome-codex-security-july-august-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/chrome-codex-security-july-august-2026-cluster/</guid><description>Chrome&apos;s July and August releases directly name OpenAI Codex Security on V8 and WebGL memory-safety vulnerabilities. - Out-of-bounds access and use-after-free in browser execution and graphics engines, severity high, credited systems OpenAI Aardvark / Codex Security (direct).</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category></item><item><title>[Finding] V12 turns a Redis sibling-eviction use-after-free into remote code execution</title><link>https://bugflation.com/findings/v12-redis-sibling-eviction-uaf/</link><guid isPermaLink="true">https://bugflation.com/findings/v12-redis-sibling-eviction-uaf/</guid><description>V12 reported and exploited a Redis blocked-client iterator flaw; upstream merged the fix and shipped it in Redis 8.8.2. - Heap use-after-free leading to remote code execution, severity high, credited systems V12 (self-reported).</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>v12</category><category>self-reported</category><category>v12:self-reported</category></item><item><title>[Finding] Fluid Attacks&apos; AI SAST adds three August CVEs</title><link>https://bugflation.com/findings/fluid-ai-sast-august-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/fluid-ai-sast-august-2026-cluster/</guid><description>Fluid Attacks&apos; public advisories directly credit its AI SAST Scanner on Zammad and LimeSurvey authorization, SQL-injection, and XSS vulnerabilities. - Improper authorization, authenticated SQL injection, and reflected XSS, severity high, credited systems Fluid Attacks AI SAST (direct).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>fluid-ai-sast</category><category>direct</category><category>fluid-ai-sast:direct</category></item><item><title>[Finding] Gitea directly credits Claude-assisted research on LFS deploy-key escalation</title><link>https://bugflation.com/findings/claude-gitea-lfs-cve-2026-58435/</link><guid isPermaLink="true">https://bugflation.com/findings/claude-gitea-lfs-cve-2026-58435/</guid><description>Gitea&apos;s upstream advisory credits Doyensec&apos;s Claude-assisted research on an LFS deploy-key privilege escalation. - Deploy-key privilege escalation in Git LFS access control, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] PostgreSQL directly credits Claude-assisted research on four RCE-class CVEs</title><link>https://bugflation.com/findings/postgresql-claude-august-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/postgresql-claude-august-2026-cluster/</guid><description>PostgreSQL&apos;s August security release credits Claude and Anthropic Research, or Claude with Ada Logics, across four high-severity server vulnerabilities. - Heap overflow, SQL injection, arbitrary-address writes, and type confusion, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] PostgreSQL directly credits Codex Security on two type-confusion RCEs</title><link>https://bugflation.com/findings/postgresql-codex-august-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/postgresql-codex-august-2026-cluster/</guid><description>PostgreSQL&apos;s August security release directly credits OpenAI Codex Security on two high-severity type-confusion vulnerabilities. - Type confusion enabling arbitrary code execution as the database operating-system user, severity high, credited systems OpenAI Aardvark / Codex Security (direct).</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category></item><item><title>[Finding] Codex Security and V12 share credit on PostgreSQL to_char RCE</title><link>https://bugflation.com/findings/postgresql-codex-v12-cve-2026-14669/</link><guid isPermaLink="true">https://bugflation.com/findings/postgresql-codex-v12-cve-2026-14669/</guid><description>PostgreSQL directly credits OpenAI Codex Security among the reporters of CVE-2026-14669, while V12 independently maps the accepted heap overflow to its public agentic research. - Heap buffer overflow enabling database-server code execution, severity high, credited systems OpenAI Aardvark / Codex Security (direct), V12 (self-reported).</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category><category>v12</category><category>self-reported</category><category>v12:self-reported</category></item><item><title>[Finding] PostgreSQL directly credits DepthFirst AI on stack buffer overflow</title><link>https://bugflation.com/findings/postgresql-depthfirst-cve-2026-14679/</link><guid isPermaLink="true">https://bugflation.com/findings/postgresql-depthfirst-cve-2026-14679/</guid><description>PostgreSQL directly thanks Zheng Yu of DepthFirst AI for reporting CVE-2026-14679, a high-severity argument-matching stack overflow. - Stack buffer overflow with controlled writes to server memory, severity high, credited systems DepthFirst (direct).</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>depthfirst</category><category>direct</category><category>depthfirst:direct</category></item><item><title>[Finding] JFrog Artifactory directly credits Claude across four authentication flaws</title><link>https://bugflation.com/findings/claude-jfrog-artifactory-august-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/claude-jfrog-artifactory-august-2026-cluster/</guid><description>JFrog&apos;s CNA records credit Ben Morris in collaboration with Claude and Anthropic Research on four Artifactory vulnerabilities. - Stale credentials, insecure deserialization, SAML verification, and remember-me authentication flaws, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] A Security uses frontier models to build Zoomsday in under a day</title><link>https://bugflation.com/findings/a-security-zoomsday-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/a-security-zoomsday-2026-cluster/</guid><description>A Security reports that fewer than twenty prompts to public frontier models uncovered and weaponized two Zoom annotation memory-safety flaws. - Remotely reachable stack overwrite and heap over-read chained into zero-click code execution, severity critical, credited systems A Security (self-reported).</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>a-security</category><category>self-reported</category><category>a-security:self-reported</category></item><item><title>[Finding] Aretiq.AI receives a Microsoft Exchange vulnerability credit</title><link>https://bugflation.com/findings/aretiq-exchange-cve-2026-62912/</link><guid isPermaLink="true">https://bugflation.com/findings/aretiq-exchange-cve-2026-62912/</guid><description>MSRC credits E. Cooper with Aretiq.AI on CVE-2026-62912, a Microsoft Exchange Server denial-of-service vulnerability. - Remote denial of service, severity medium, credited systems Aretiq.AI (self-reported).</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>aretiq-ai</category><category>self-reported</category><category>aretiq-ai:self-reported</category></item><item><title>[Finding] Microsoft directly credits Enclave AI on Teams for Android spoofing</title><link>https://bugflation.com/findings/enclave-teams-android-cve-2026-65767/</link><guid isPermaLink="true">https://bugflation.com/findings/enclave-teams-android-cve-2026-65767/</guid><description>MSRC directly credits Enclave AI on CVE-2026-65767, a high-severity Microsoft Teams for Android spoofing vulnerability. - Mobile-client spoofing and trust-boundary failure, severity high, credited systems Enclave AI (direct).</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>enclave-ai</category><category>direct</category><category>enclave-ai:direct</category></item><item><title>[Finding] Rapid7&apos;s agentic SharePoint campaign yields a two-CVE unauthenticated-RCE chain</title><link>https://bugflation.com/findings/rapid7-sharepoint-agentic-rce-chain/</link><guid isPermaLink="true">https://bugflation.com/findings/rapid7-sharepoint-agentic-rce-chain/</guid><description>Rapid7 Labs reports that a heavily prompted agent helped produce an authentication-bypass and remote-code-execution chain against SharePoint. - JWT authentication bypass chained with authenticated remote code execution, severity critical, credited systems Rapid7 Labs Agentic Research Workflow (self-reported).</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>rapid7-agentic-research</category><category>self-reported</category><category>rapid7-agentic-research:self-reported</category></item><item><title>[Finding] V12 chains two Dolphin DSP-HLE memory flaws into a guest-to-host escape</title><link>https://bugflation.com/findings/v12-dolphin-guest-to-host-rce-chain/</link><guid isPermaLink="true">https://bugflation.com/findings/v12-dolphin-guest-to-host-rce-chain/</guid><description>A Zelda audio stack disclosure defeats ASLR and an AX parameter-block stack write installs a ROP chain, producing host code execution from a GameCube guest. - Out-of-bounds stack read and indexed stack write chained into guest-to-host code execution, severity high, credited systems V12 (self-reported).</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>v12</category><category>self-reported</category><category>v12:self-reported</category></item><item><title>[Finding] XBreach&apos;s Microsoft credit wave spans nine Windows and Azure CVEs</title><link>https://bugflation.com/findings/xbreach-microsoft-july-august-2026-wave/</link><guid isPermaLink="true">https://bugflation.com/findings/xbreach-microsoft-july-august-2026-wave/</guid><description>MSRC credits XBreach across nine public CVEs spanning Windows, Edge, Azure AI Search, CycleCloud, App Service, and Confidential Ledger. - Privilege escalation, RCE, security-feature bypass, and information disclosure, severity critical, credited systems XBREACH (self-reported).</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>xbreach</category><category>self-reported</category><category>xbreach:self-reported</category></item><item><title>[Finding] Microsoft directly credits Xint on Win32k information disclosure</title><link>https://bugflation.com/findings/xint-microsoft-cve-2026-62746/</link><guid isPermaLink="true">https://bugflation.com/findings/xint-microsoft-cve-2026-62746/</guid><description>MSRC directly credits Theori working with Xint on CVE-2026-62746, a Win32k information-disclosure vulnerability. - Information disclosure, severity medium, credited systems Xint Code (direct).</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>xint-code</category><category>direct</category><category>xint-code:direct</category></item><item><title>[Finding] pwn.ai autonomously chains WordPress XSS into code execution</title><link>https://bugflation.com/findings/pwn-ai-wordpress-cve-2026-64638/</link><guid isPermaLink="true">https://bugflation.com/findings/pwn-ai-wordpress-cve-2026-64638/</guid><description>pwn.ai reports an autonomous open-model workflow that found and chained CVE-2026-64638 from pre-authentication reflected XSS into conditional RCE. - Pre-authentication reflected XSS chained into conditional remote code execution, severity high, credited systems pwn.ai (self-reported).</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>pwn-ai</category><category>self-reported</category><category>pwn-ai:self-reported</category></item><item><title>[Finding] Argus discloses four OP-TEE and OpenBSD CVEs</title><link>https://bugflation.com/findings/argus-august-2026-optee-openbsd-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/argus-august-2026-optee-openbsd-cluster/</guid><description>Argus&apos; public Proof of Possession tracker discloses three OP-TEE memory-safety CVEs and an OpenBSD wireless countermeasure flaw. - Heap underwrite, use-after-free, secure-world denial of service, and wireless countermeasure logic failure, severity high, credited systems Argus / ByteRay (self-reported).</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>argus-bytteray</category><category>self-reported</category><category>argus-bytteray:self-reported</category></item><item><title>[Finding] Apple directly credits BynarIO Atlas on Screen Sharing root RCE</title><link>https://bugflation.com/findings/bynario-apple-screen-sharing-cve-2026-65400/</link><guid isPermaLink="true">https://bugflation.com/findings/bynario-apple-screen-sharing-cve-2026-65400/</guid><description>Apple directly credits BynarIO Atlas on CVE-2026-65400, a pre-authentication Screen Sharing vulnerability with root code-execution impact. - Pre-authentication remote code execution as root, severity critical, credited systems BynarIO AI (direct).</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>bynario-ai</category><category>direct</category><category>bynario-ai:direct</category></item><item><title>[Finding] Chrome directly credits XBOW on three WebAudio and V8 CVEs</title><link>https://bugflation.com/findings/chrome-xbow-july-august-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/chrome-xbow-july-august-2026-cluster/</guid><description>Chrome&apos;s July and August releases directly credit XBOW on three high-severity browser vulnerabilities. - WebAudio type confusion and implementation flaws plus V8 memory safety, severity high, credited systems XBOW (direct).</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>xbow</category><category>direct</category><category>xbow:direct</category></item><item><title>[Finding] Striga adds an Electron DevTools injection CVE</title><link>https://bugflation.com/findings/striga-electron-cve-2026-70609/</link><guid isPermaLink="true">https://bugflation.com/findings/striga-electron-cve-2026-70609/</guid><description>Striga&apos;s public tracker attributes CVE-2026-70609 to its AI auditing platform; Electron fixed the DevTools JavaScript-injection issue. - JavaScript injection through an unsanitized DevTools parameter, severity medium, credited systems Striga AI (self-reported).</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>striga-ai</category><category>self-reported</category><category>striga-ai:self-reported</category></item><item><title>[Finding] Caliptra directly credits Claude on two secure-boot and debug-unlock flaws</title><link>https://bugflation.com/findings/claude-caliptra-august-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/claude-caliptra-august-2026-cluster/</guid><description>Caliptra&apos;s CNA records credit Alex Matrosov with Claude, Anthropic on a secure-boot TOCTOU bypass and a device-binding weakness. - Secure-boot TOCTOU bypass and production debug-token device-binding weakness, severity medium, credited systems Claude / Anthropic Research (direct).</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Bouncy Castle records twenty-nine Claude-assisted CVEs</title><link>https://bugflation.com/findings/claude-bouncycastle-2026-29-cve-wave/</link><guid isPermaLink="true">https://bugflation.com/findings/claude-bouncycastle-2026-29-cve-wave/</guid><description>Bouncy Castle and CVE records directly credit Alex Gaynor working with Claude and Anthropic Research across twenty-nine 2026 Java security fixes. - Cryptographic validation, protocol, parsing, memory, and authentication flaws, severity critical, credited systems Claude / Anthropic Research (direct).</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Apple credits Atuin and BynarIO on a Screen Sharing access-control CVE</title><link>https://bugflation.com/findings/apple-atuin-bynario-screen-sharing-cve-2026-43760/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-atuin-bynario-screen-sharing-cve-2026-43760/</guid><description>Apple&apos;s July security notes name the Atuin Automated Vulnerability Discovery Engine and BynarIO among the credits for CVE-2026-43760. - Screen Sharing access-control weakness, severity high, credited systems Atuin Automated Vulnerability Discovery Engine (direct), BynarIO AI (direct).</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>atuin</category><category>direct</category><category>atuin:direct</category><category>bynario-ai</category><category>bynario-ai:direct</category></item><item><title>[Finding] Apple&apos;s July security wave directly credits Claude on three memory-safety CVEs</title><link>https://bugflation.com/findings/apple-claude-july-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-claude-july-2026-cluster/</guid><description>Apple credits Claude-assisted researchers on SMB, WebDAV, and WebKit memory-safety issues across its July 27 platform releases. - Type confusion, use-after-free, and browser memory corruption, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Apple directly credits Z.AI GLM on a WebKit use-after-free</title><link>https://bugflation.com/findings/apple-glm-webkit-cve-2026-64783/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-glm-webkit-cve-2026-64783/</guid><description>Apple&apos;s July 27 security notes name a researcher using GLM from Z.AI on CVE-2026-64783, a WebKit use-after-free. - WebKit use-after-free, severity high, credited systems Z.AI GLM (direct).</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zai-glm</category><category>direct</category><category>zai-glm:direct</category></item><item><title>[Finding] Apple credits XBreach.ai on a CUPS root-privilege vulnerability</title><link>https://bugflation.com/findings/apple-xbreach-cups-cve-2026-39875/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-xbreach-cups-cve-2026-39875/</guid><description>Apple&apos;s July 27 macOS security notes credit XBreach.ai among the reporters of CVE-2026-39875, a CUPS issue with root-privilege impact. - Local privilege escalation to root, severity high, credited systems XBREACH (self-reported).</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>xbreach</category><category>self-reported</category><category>xbreach:self-reported</category></item><item><title>[Finding] Apple directly credits ThreatBook XGPT across four system CVEs</title><link>https://bugflation.com/findings/apple-xgpt-june-july-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-xgpt-june-july-2026-cluster/</guid><description>Apple names researchers using ThreatBook XGPT on four kernel, SMB, and Libnotify vulnerabilities disclosed in June and July 2026. - Kernel state disclosure and use-after-free, SMB remote denial of service, and Libnotify out-of-bounds write, severity high, credited systems ThreatBook XGPT (direct).</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>threatbook-xgpt</category><category>direct</category><category>threatbook-xgpt:direct</category></item><item><title>[Finding] Apple&apos;s July release directly credits Xint on two kernel CVEs</title><link>https://bugflation.com/findings/apple-xint-july-2026-kernel-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-xint-july-2026-kernel-cluster/</guid><description>Apple directly credits Xint-assisted research on a kernel information leak and an uninitialized-memory issue in its July 27 releases. - Kernel information disclosure, uninitialized memory, and memory corruption, severity high, credited systems Xint Code (direct).</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>xint-code</category><category>direct</category><category>xint-code:direct</category></item><item><title>[Finding] BynarIO maps a Linux TIPC broadcast parser flaw to CVE-2026-64450</title><link>https://bugflation.com/findings/bynario-linux-tipc-cve-2026-64450/</link><guid isPermaLink="true">https://bugflation.com/findings/bynario-linux-tipc-cve-2026-64450/</guid><description>BynarIO says its AI research found an out-of-bounds read in Linux TIPC broadcast Gap ACK handling, fixed upstream as CVE-2026-64450. - Out-of-bounds read in broadcast Gap ACK block parsing, severity medium, credited systems BynarIO AI (self-reported).</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>bynario-ai</category><category>self-reported</category><category>bynario-ai:self-reported</category></item><item><title>[Finding] OpenAI evaluation agents escape a benchmark and reach Hugging Face production</title><link>https://bugflation.com/findings/openai-exploitgym-hugging-face-incident/</link><guid isPermaLink="true">https://bugflation.com/findings/openai-exploitgym-hugging-face-incident/</guid><description>During an authorized cyber-capability evaluation, OpenAI agents autonomously found and chained previously unknown flaws across an Artifactory proxy and Hugging Face infrastructure. - Package-proxy compromise chained with local-file disclosure and server-side template injection, severity critical, credited systems OpenAI ExploitGym Evaluation Agents (direct).</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>openai-exploitgym</category><category>direct</category><category>openai-exploitgym:direct</category></item><item><title>July 2026 Source Audit: The Public Ledger Broadens</title><link>https://bugflation.com/articles/july-2026-source-audit/</link><guid isPermaLink="true">https://bugflation.com/articles/july-2026-source-audit/</guid><description>A primary-source audit adds post-cutoff disclosures, backfills public campaigns, preserves shared attribution, and separates tracker claims from upstream severity.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>audit</category><category>evidence</category><category>methodology</category><author>Bugflation Editorial</author></item><item><title>[Finding] AISLE and Claude Mythos independently report Squid FTP memory disclosure</title><link>https://bugflation.com/findings/cve-2026-47729-squid-aisle-mythos/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-47729-squid-aisle-mythos/</guid><description>Squid&apos;s advisory records independent reports from AISLE and Calif/Anthropic researchers for an FTP gateway response-smuggling flaw that can expose worker memory. - Response smuggling and process-memory disclosure, severity medium, credited systems AISLE (self-reported), Claude Mythos Preview (direct).</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category><category>claude-mythos</category><category>direct</category><category>claude-mythos:direct</category></item><item><title>[Finding] Microsoft credits Doyensec collaboration with Claude on USB Hub EoP</title><link>https://bugflation.com/findings/cve-2026-50479-windows-usb-claude/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-50479-windows-usb-claude/</guid><description>Microsoft directly credits Doyensec researchers working with Claude and Anthropic Research for a Windows USB Hub Driver elevation-of-privilege vulnerability. - Untrusted pointer dereference and elevation of privilege, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] AISLE&apos;s July disclosure stream spans ten CVEs in seven projects</title><link>https://bugflation.com/findings/aisle-july-2026-multiproject-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/aisle-july-2026-multiproject-cluster/</guid><description>AISLE&apos;s public registry links ten newly disclosed CVEs to its AI-native engine across Foreman, Gitea, Joomla, Wireshark, dhcpcd, n8n, and alsa-lib. - Authorization, injection, XSS, parser, denial-of-service, and memory-safety flaws, severity high, credited systems AISLE (self-reported).</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category></item><item><title>[Finding] XGPT finds three libseccomp filter-generation vulnerabilities</title><link>https://bugflation.com/findings/xgpt-libseccomp-ghsa-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/xgpt-libseccomp-ghsa-cluster/</guid><description>Three upstream advisories directly credit Feng Xue with XGPT for a filter-policy weakening bug, a double-free, and heap corruption in oversized BPF generation. - Incorrect security-policy generation, double-free, and heap corruption, severity medium, credited systems ThreatBook XGPT (direct).</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>threatbook-xgpt</category><category>direct</category><category>threatbook-xgpt:direct</category></item><item><title>[Finding] Chrome directly credits Codex Security on V8 type-confusion CVE</title><link>https://bugflation.com/findings/chrome-openai-v8-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/chrome-openai-v8-2026-cluster/</guid><description>Chrome 150 directly credits OpenAI Codex Security on CVE-2026-14431, a High-severity V8 type confusion published in June 2026. - Type confusion, severity high, credited systems OpenAI Aardvark / Codex Security (direct), OpenAI Daybreak (direct).</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category><category>openai-daybreak</category><category>openai-daybreak:direct</category></item><item><title>[Finding] Chrome credits Theori with Xint Code on FFmpeg out-of-bounds read</title><link>https://bugflation.com/findings/cve-2026-13858-chrome-xint-code/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-13858-chrome-xint-code/</guid><description>Chrome 150 directly credits Wongi Lee of Theori with Xint Code, alongside Jungwoo Lee, for a Medium-severity FFmpeg out-of-bounds read. - Out-of-bounds read, severity medium, credited systems Xint Code (direct).</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>xint-code</category><category>direct</category><category>xint-code:direct</category></item><item><title>[Finding] Chrome directly credits pwn.ai on security-UI CVE</title><link>https://bugflation.com/findings/cve-2026-14077-chrome-pwn-ai/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-14077-chrome-pwn-ai/</guid><description>Chrome 150 credits pwn.ai for a Low-severity incorrect security UI issue in Select, providing direct vendor attribution for the autonomous pentesting platform. - Incorrect security UI, severity low, credited systems pwn.ai (direct).</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>low</category><category>pwn-ai</category><category>direct</category><category>pwn-ai:direct</category></item><item><title>[Finding] FreeBSD credits OpenAI Codex Security on two POSIX shared-memory CVEs</title><link>https://bugflation.com/findings/freebsd-codex-posixshm-cve-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/freebsd-codex-posixshm-cve-cluster/</guid><description>FreeBSD directly credits the OpenAI Codex Security Team for two POSIX shared-memory flaws with local kernel privilege-escalation impact. - Kernel memory corruption and local privilege escalation, severity high, credited systems OpenAI Aardvark / Codex Security (direct).</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category></item><item><title>[Finding] FreeBSD advisories directly credit Z.AI GLM across eight CVEs</title><link>https://bugflation.com/findings/freebsd-glm-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/freebsd-glm-2026-cluster/</guid><description>FreeBSD credits Z.AI GLM-assisted research on eight vulnerabilities spanning ptrace, threads, jails, unlinkat, kernel TLS, and ZFS. - Privilege escalation, use-after-free, state leakage, and filesystem boundary failures, severity high, credited systems Z.AI GLM (direct).</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zai-glm</category><category>direct</category><category>zai-glm:direct</category></item><item><title>[Finding] Atuin and AISLE converge on FreeBSD libalias stack overflow</title><link>https://bugflation.com/findings/freebsd-libalias-atuin-aisle-cve-2026-49420/</link><guid isPermaLink="true">https://bugflation.com/findings/freebsd-libalias-atuin-aisle-cve-2026-49420/</guid><description>FreeBSD&apos;s libalias advisory directly credits Atuin-assisted research, while AISLE independently claims discovery of the same remotely reachable stack-overflow CVE. - Remotely reachable stack buffer overflow, severity high, credited systems Atuin Automated Vulnerability Discovery Engine (direct), AISLE (self-reported).</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>atuin</category><category>direct</category><category>atuin:direct</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category></item><item><title>[Finding] V12 publishes twelve accepted Miden Node findings</title><link>https://bugflation.com/findings/v12-miden-node-twelve-finding-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/v12-miden-node-twelve-finding-cluster/</guid><description>V12&apos;s public campaign records twelve autonomously discovered Miden Node issues with linked upstream reports and responsive fixes or pull requests. - Validation, denial-of-service, state-consistency, and protocol-logic flaws, severity high, credited systems V12 (self-reported).</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>v12</category><category>self-reported</category><category>v12:self-reported</category></item><item><title>[Finding] Apple credits Codex Security on three June 2026 WebKit CVEs</title><link>https://bugflation.com/findings/apple-webkit-june-2026-codex-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-webkit-june-2026-codex-cluster/</guid><description>Apple&apos;s June 29 security release directly names OpenAI Codex Security on three WebKit memory-safety vulnerabilities, including one explicit out-of-bounds write. - Memory corruption, memory-handling crash, and out-of-bounds write, severity high, credited systems OpenAI Aardvark / Codex Security (direct).</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category></item><item><title>[Finding] Apple credits researchers using Z.AI GLM on WebKit CVE</title><link>https://bugflation.com/findings/cve-2026-43663-apple-webkit-zai-glm/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-43663-apple-webkit-zai-glm/</guid><description>Apple&apos;s June security release explicitly says researchers used GLM from Z.AI while reporting a WebKit memory-handling vulnerability. - WebKit memory-handling failure and browser crash, severity high, credited systems Z.AI GLM (direct).</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zai-glm</category><category>direct</category><category>zai-glm:direct</category></item><item><title>[Finding] Apple credits Claude on WebKit use-after-free</title><link>https://bugflation.com/findings/cve-2026-43715-apple-webkit-claude/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-43715-apple-webkit-claude/</guid><description>Apple directly credits Milad Nasr and Nicholas Carlini working with Claude and Anthropic on a WebKit use-after-free that can cause memory corruption. - Use-after-free and browser memory corruption, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] V12 reports storage-exhaustion and GC bypass in NEAR Intents</title><link>https://bugflation.com/findings/v12-near-intents-storage-exhaustion/</link><guid isPermaLink="true">https://bugflation.com/findings/v12-near-intents-storage-exhaustion/</guid><description>V12 says its autonomous analysis found a garbage-collection bypass that could drive persistent storage growth in NEAR Intents; maintainers acknowledged and mitigated it. - Storage exhaustion and garbage-collection bypass, severity medium, credited systems V12 (self-reported).</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>v12</category><category>self-reported</category><category>v12:self-reported</category></item><item><title>[Finding] V12 finds plaintext GridPlus pairing credentials in Rabby Wallet</title><link>https://bugflation.com/findings/v12-rabby-gridplus-pairing-credentials/</link><guid isPermaLink="true">https://bugflation.com/findings/v12-rabby-gridplus-pairing-credentials/</guid><description>V12 reports that its autonomous audit found Rabby Wallet storing sensitive GridPlus hardware-wallet pairing material in plaintext; the report received a bug bounty. - Plaintext storage of hardware-wallet pairing credentials, severity medium, credited systems V12 (self-reported).</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>v12</category><category>self-reported</category><category>v12:self-reported</category></item><item><title>[Finding] curl 8.21.0 credits AISLE Research on six CVEs</title><link>https://bugflation.com/findings/aisle-curl-8-21-cve-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/aisle-curl-8-21-cve-cluster/</guid><description>curl&apos;s June 2026 security release directly credits Joshua Rogers of AISLE Research on six vulnerabilities spanning authentication state, credentials, memory safety, and protocol handling. - Double-free, credential disclosure, authentication-state leakage, and protocol confusion, severity medium, credited systems AISLE (self-reported).</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category></item><item><title>[Finding] Linux fixes explicitly credit Claude-assisted review across four CVEs</title><link>https://bugflation.com/findings/claude-linux-kernel-review-cve-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/claude-linux-kernel-review-cve-cluster/</guid><description>Upstream Linux fixes describe Claude Code or Claude model review surfacing four security bugs in packet sockets, EDAC, nfsd, and amd-pstate. - Use-after-free, ordering failure, and kernel resource leaks, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Mythos finds curl STARTTLS connection-reuse flaw</title><link>https://bugflation.com/findings/cve-2026-8286-curl-mythos/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-8286-curl-mythos/</guid><description>curl credits Andrew Nesbitt, powered by Mythos, for a connection-reuse error that could keep using a plaintext connection when STARTTLS was requested. - Incorrect STARTTLS connection reuse, severity low, credited systems Claude Mythos Preview (direct).</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>low</category><category>claude-mythos</category><category>direct</category><category>claude-mythos:direct</category></item><item><title>The CVE Layer Is Becoming the Bottleneck</title><link>https://bugflation.com/articles/cve-layer-is-becoming-the-bottleneck/</link><guid isPermaLink="true">https://bugflation.com/articles/cve-layer-is-becoming-the-bottleneck/</guid><description>AI-enabled discovery is increasing pressure on vulnerability identifiers, advisory quality, attribution, and disclosure workflows.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>cve</category><category>disclosure</category><category>evidence</category><category>operations</category><author>Bugflation Editorial</author></item><item><title>[Finding] Codex-assisted HTTP/2 Bomb reaches Apache and other major servers</title><link>https://bugflation.com/findings/cve-2026-49975-http2-bomb-codex/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-49975-http2-bomb-codex/</guid><description>Calif used OpenAI Codex to identify a denial-of-service technique affecting major HTTP/2 implementations; Apache assigned CVE-2026-49975 to its mod_http2 variant. - HTTP/2 denial of service through decompression work amplification, severity medium, credited systems OpenAI Aardvark / Codex Security (direct), OpenAI Daybreak (direct).</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category><category>openai-daybreak</category><category>openai-daybreak:direct</category></item><item><title>[Finding] GPT-5.5 safety evaluation surfaces high-severity Firefox WebAssembly UAF</title><link>https://bugflation.com/findings/cve-2026-8390-firefox-openai-gpt55/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-8390-firefox-openai-gpt55/</guid><description>Mozilla credits OpenAI Preparedness and Bill Demirkapi on a high-impact Firefox WebAssembly use-after-free; OpenAI says GPT-5.5 found it during safety evaluation. - Use-after-free in browser JavaScript engine, severity high, credited systems OpenAI Daybreak (direct).</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-daybreak</category><category>direct</category><category>openai-daybreak:direct</category></item><item><title>[Finding] Calif and Codex validate three FreeBSD local-privilege-escalation CVEs</title><link>https://bugflation.com/findings/openai-calif-freebsd-lpe-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/openai-calif-freebsd-lpe-cluster/</guid><description>OpenAI says Calif researchers used Codex to find and validate proof-of-concept exploits for three FreeBSD vulnerabilities fixed in May 2026. - Use-after-free, credential confusion, and local privilege escalation, severity high, credited systems OpenAI Aardvark / Codex Security (direct), OpenAI Daybreak (direct).</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category><category>openai-daybreak</category><category>openai-daybreak:direct</category></item><item><title>[Finding] Codex Security independently identifies four fixed dnsmasq CVEs</title><link>https://bugflation.com/findings/openai-codex-dnsmasq-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/openai-codex-dnsmasq-2026-cluster/</guid><description>OpenAI says Codex Security independently identified vulnerable patterns corresponding to four dnsmasq CVEs fixed in the 2.92rel2 security release. - DNS and DHCP parser memory-safety and denial-of-service flaws, severity medium, credited systems OpenAI Aardvark / Codex Security (direct), OpenAI Daybreak (direct).</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category><category>openai-daybreak</category><category>openai-daybreak:direct</category></item><item><title>[Finding] OpenAI Daybreak finds and patches 23-year-old OpenBSD semaphore UAF</title><link>https://bugflation.com/findings/openai-daybreak-openbsd-semaphore-uaf/</link><guid isPermaLink="true">https://bugflation.com/findings/openai-daybreak-openbsd-semaphore-uaf/</guid><description>OpenAI reports that its models found a 23-year-old use-after-free in OpenBSD System V semaphores that could permit local root escalation; OpenBSD accepted the patch. - Use-after-free and local privilege escalation, severity high, credited systems OpenAI Daybreak (direct).</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-daybreak</category><category>direct</category><category>openai-daybreak:direct</category></item><item><title>[Finding] Claude-credited LibreOffice June 2026 document-import cluster</title><link>https://bugflation.com/findings/claude-libreoffice-june-2026-document-import-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/claude-libreoffice-june-2026-document-import-cluster/</guid><description>The Document Foundation credits Anthropic automated discovery using Claude for seven LibreOffice memory-safety CVEs across PPT, Calc, ODF, DXF, EMF+, and OOXML import paths. - Document parser memory-safety vulnerabilities, severity medium, credited systems Claude / Anthropic Research (direct).</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Cloud Foundry UAA credits Claude-assisted reports for two authentication CVEs</title><link>https://bugflation.com/findings/cloudfoundry-uaa-claude-2026-auth-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/cloudfoundry-uaa-claude-2026-auth-cluster/</guid><description>Cloud Foundry UAA advisories credit Ada Logics in collaboration with Claude and Anthropic Research for a critical EC private-key exposure and a SAML encrypted-assertion authentication bypass. - Authentication bypass and key disclosure, severity critical, credited systems Claude / Anthropic Research (direct).</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Argus finds cross-user dashboard disclosure in Zabbix report.test</title><link>https://bugflation.com/findings/argus-zabbix-report-test-idor/</link><guid isPermaLink="true">https://bugflation.com/findings/argus-zabbix-report-test-idor/</guid><description>A low-privilege user could select another user&apos;s identity, make Zabbix render that user&apos;s dashboard, and receive the resulting PDF by email. - Insecure direct object reference and broken authorization, severity high, credited systems Argus (self-reported).</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>argus-bytteray</category><category>self-reported</category><category>argus-bytteray:self-reported</category></item><item><title>[Finding] MSRC May and June credits add five Claude-assisted Windows CVEs</title><link>https://bugflation.com/findings/microsoft-claude-windows-may-june-2026-credits/</link><guid isPermaLink="true">https://bugflation.com/findings/microsoft-claude-windows-may-june-2026-credits/</guid><description>Microsoft&apos;s May and June 2026 CVRF records credit Calif.io, Doyensec, and Anthropic researchers working with Claude and Anthropic Research on five Windows CVEs. - Windows graphics, kernel, RDP, storage, and VMSwitch vulnerabilities, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] MSRC credits Codex collaboration for HTTP.sys denial of service</title><link>https://bugflation.com/findings/microsoft-codex-httpsys-cve-2026-49160/</link><guid isPermaLink="true">https://bugflation.com/findings/microsoft-codex-httpsys-cve-2026-49160/</guid><description>Microsoft&apos;s June 2026 CVRF feed credits Quang Luong of Calif.io in collaboration with Codex for CVE-2026-49160, an HTTP.sys HTTP/2 denial-of-service vulnerability. - HTTP/2 resource-consumption denial of service, severity high, credited systems OpenAI Aardvark / Codex Security (direct).</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category></item><item><title>[Finding] OpenSSL credits Claude-assisted Calif.io report for PKCS7_verify use-after-free</title><link>https://bugflation.com/findings/openssl-claude-pkcs7-uaf-cve-2026-45447/</link><guid isPermaLink="true">https://bugflation.com/findings/openssl-claude-pkcs7-uaf-cve-2026-45447/</guid><description>OpenSSL&apos;s June 2026 vulnerability database credits Thai Duong of Calif.io in collaboration with Claude and Anthropic Research for CVE-2026-45447, a high-severity PKCS7_verify() heap use-after-free. - PKCS7/S/MIME heap use-after-free, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Striga&apos;s public tracker adds eighteen validated CVEs across eleven projects</title><link>https://bugflation.com/findings/striga-2025-2026-cve-backfill/</link><guid isPermaLink="true">https://bugflation.com/findings/striga-2025-2026-cve-backfill/</guid><description>Striga&apos;s AI-auditing record extends beyond its existing Apache entry into Logseq, Shiro, Apple container, Ollama, pac4j, Tomcat, axios, n8n, Mattermost, OpenClaw, and FreshRSS. - RCE, authorization bypass, credential theft, denial-of-service, and injection flaws, severity critical, credited systems Striga AI (self-reported).</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>striga-ai</category><category>self-reported</category><category>striga-ai:self-reported</category></item><item><title>[Finding] Apache httpd credits AISLE Research on two 2.4.68 CVEs</title><link>https://bugflation.com/findings/aisle-apache-httpd-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/aisle-apache-httpd-2026-cluster/</guid><description>Apache&apos;s upstream 2.4.68 security record credits AISLE Research on two vulnerabilities in HTTP Server request and module handling. - Request-processing and module-boundary vulnerabilities, severity low, credited systems AISLE (self-reported).</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>low</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category></item><item><title>[Finding] Argus finds SSH identity confusion in libcurl connection reuse</title><link>https://bugflation.com/findings/argus-curl-ssh-connection-reuse/</link><guid isPermaLink="true">https://bugflation.com/findings/argus-curl-ssh-connection-reuse/</guid><description>libcurl could reuse an SSH or SFTP connection authenticated with a different key, causing a later request to execute under the wrong identity. - Authentication-context confusion in connection pooling, severity high, credited systems Argus (self-reported).</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>argus-bytteray</category><category>self-reported</category><category>argus-bytteray:self-reported</category></item><item><title>[Finding] DepthFirst and Striga share credit on Apache httpd heap underflow</title><link>https://bugflation.com/findings/cve-2026-44631-apache-depthfirst-striga/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-44631-apache-depthfirst-striga/</guid><description>Apache&apos;s 2.4.68 security record credits both DepthFirst and Bartlomiej Dmitruk of Striga on a heap-underflow vulnerability. - Heap underflow, severity low, credited systems DepthFirst (self-reported), Striga AI (self-reported).</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>low</category><category>depthfirst</category><category>self-reported</category><category>depthfirst:self-reported</category><category>striga-ai</category><category>striga-ai:self-reported</category></item><item><title>[Finding] Apache httpd 2.4.68 credits DepthFirst across six additional CVEs</title><link>https://bugflation.com/findings/depthfirst-apache-httpd-2026-cve-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/depthfirst-apache-httpd-2026-cve-cluster/</guid><description>Apache&apos;s upstream security page credits DepthFirst researchers on six vulnerabilities spanning request handling, modules, and memory safety in the 2.4.68 release. - Request-processing, module-boundary, denial-of-service, and memory-safety flaws, severity medium, credited systems DepthFirst (self-reported).</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>depthfirst</category><category>self-reported</category><category>depthfirst:self-reported</category></item><item><title>[Finding] Calif.io credits OpenAI Codex on FFmpeg parser CVE</title><link>https://bugflation.com/findings/openai-codex-califio-apache-ffmpeg-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/openai-codex-califio-apache-ffmpeg-2026-cluster/</guid><description>The public CVE record credits Quang Luong of Calif.io in collaboration with OpenAI Codex for an FFmpeg DVD subtitle parser memory-safety bug. - Signed integer overflow and media-parser memory corruption, severity medium, credited systems OpenAI Aardvark / Codex Security (direct).</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category></item><item><title>[Finding] TYPO3 credits Doyensec and Claude for HTML Sanitizer XSS</title><link>https://bugflation.com/findings/typo3-claude-html-sanitizer-cve-2026-47345/</link><guid isPermaLink="true">https://bugflation.com/findings/typo3-claude-html-sanitizer-cve-2026-47345/</guid><description>TYPO3&apos;s June 2026 advisory credits IPC Labs and Doyensec in collaboration with Claude and Anthropic Research for CVE-2026-47345, an HTML Sanitizer namespace-attribute XSS bypass. - Cross-site scripting sanitizer bypass, severity medium, credited systems Claude / Anthropic Research (direct).</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Claude discovers OpenMeter SQL injection triaged by Anvil Secure</title><link>https://bugflation.com/findings/claude-openmeter-anvil-sql-injection-cve-2026-8462/</link><guid isPermaLink="true">https://bugflation.com/findings/claude-openmeter-anvil-sql-injection-cve-2026-8462/</guid><description>GitHub&apos;s reviewed advisory for CVE-2026-8462 says Claude, Anthropic&apos;s AI assistant, discovered an OpenMeter SQL injection that Anvil Secure triaged with Anthropic Research. - Authenticated SQL injection in meter creation, severity medium, credited systems Claude / Anthropic Research (direct).</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] DepthFirst publishes twenty-one fixed FFmpeg zero-days</title><link>https://bugflation.com/findings/depthfirst-ffmpeg-21-zero-day-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/depthfirst-ffmpeg-21-zero-day-cluster/</guid><description>DepthFirst says its autonomous agents found 21 reachable FFmpeg vulnerabilities; nine received consecutive CVEs and twelve additional issues were fixed upstream without public CVE IDs. - Heap and stack overflows, integer overflow, and out-of-bounds access, severity high, credited systems DepthFirst (self-reported).</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>depthfirst</category><category>self-reported</category><category>depthfirst:self-reported</category></item><item><title>[Finding] Chrome credits OpenAI researcher on V8 out-of-bounds write</title><link>https://bugflation.com/findings/chrome-openai-v8-cve-2026-9973/</link><guid isPermaLink="true">https://bugflation.com/findings/chrome-openai-v8-cve-2026-9973/</guid><description>Chrome credits amyb of OpenAI on CVE-2026-9973, a High-severity V8 out-of-bounds write that aligns with OpenAI Daybreak&apos;s public five-bug Chrome campaign. - Out-of-bounds write, severity high, credited systems OpenAI Daybreak (self-reported).</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-daybreak</category><category>self-reported</category><category>openai-daybreak:self-reported</category></item><item><title>[Finding] Joomla credits Doyensec and Claude on three May 2026 CMS CVEs</title><link>https://bugflation.com/findings/joomla-claude-doyensec-may-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/joomla-claude-doyensec-may-2026-cluster/</guid><description>Joomla&apos;s May 26, 2026 security advisories credit Doyensec in collaboration with Claude and Anthropic Research for local file inclusion, path traversal, and MFA bypass vulnerabilities. - Local file inclusion, path traversal, and authentication bypass, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] GitHub&apos;s AI-agent index adds eight fixed 7-Zip CVEs</title><link>https://bugflation.com/findings/github-security-lab-ai-agent-7zip-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/github-security-lab-ai-agent-7zip-cluster/</guid><description>Two GitHub Security Lab pages categorized as AI-agent discoveries document eight 7-Zip CVEs and one additional no-CVE report fixed in 7-Zip 26.01. - Heap buffer overflow, memory disclosure, out-of-bounds access, integer overflow, and path traversal, severity high, credited systems GitHub Security Lab AI agent (unspecified) (direct).</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>github-security-lab-ai-agent-unspecified</category><category>direct</category><category>github-security-lab-ai-agent-unspecified:direct</category></item><item><title>[Finding] GitHub Taskflow Agent yields 24 accepted reports without CVEs</title><link>https://bugflation.com/findings/github-taskflow-accepted-no-cve-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/github-taskflow-accepted-no-cve-cluster/</guid><description>Twenty-four Taskflow and GHSL-agent reports were publicly accepted or fixed across 23 no-CVE advisory pages covering twenty projects. - SQL injection, attachment exfiltration, authorization bypass, action injection, and data exposure, severity high, credited systems GitHub Security Lab Taskflow Agent (direct).</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>github-security-lab-taskflow</category><category>direct</category><category>github-security-lab-taskflow:direct</category></item><item><title>[Finding] FreeBSD credits AISLE Research on three more May 2026 CVEs</title><link>https://bugflation.com/findings/aisle-freebsd-may-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/aisle-freebsd-may-2026-cluster/</guid><description>FreeBSD&apos;s May 20 advisory batch credits Joshua Rogers of AISLE Research on stack and heap overflows and a capability-limit bypass. - Stack overflow, heap overflow, and capability-sandbox bypass, severity high, credited systems AISLE (self-reported).</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category></item><item><title>[Finding] Anthropic CVD dashboard reveals fixed Mythos Preview open-source findings</title><link>https://bugflation.com/findings/anthropic-cvd-may-2026-mythos-oss-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/anthropic-cvd-may-2026-mythos-oss-cluster/</guid><description>Anthropic&apos;s Project Glasswing CVD dashboard revealed 27 fixed, CVE/GHSA-backed open-source entries attributed to Claude Mythos Preview, including NGINX, wolfSSL, Nomad, Temporal, Mastodon, FreeRDP, jq, MapServer, Gitoxide, Ghost, Craft CMS, and other projects. - Project Glasswing CVD cluster: path traversal, broken access control, SSRF, heap overflow, SQL injection, RCE, and privilege escalation, severity critical, credited systems Claude Mythos Preview (direct).</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>claude-mythos</category><category>direct</category><category>claude-mythos:direct</category></item><item><title>[Finding] Symfony credits Claude Mythos on SMTP command-injection CVE</title><link>https://bugflation.com/findings/cve-2026-45067-symfony-mythos/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-45067-symfony-mythos/</guid><description>Symfony credits Claude Mythos Preview via Project Glasswing for finding and helping fix a CRLF injection in Mime Address handling. - Email header and SMTP command injection, severity medium, credited systems Claude Mythos Preview (direct).</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>claude-mythos</category><category>direct</category><category>claude-mythos:direct</category></item><item><title>[Finding] Gemini CLI and review agents surface four Linux kernel CVEs</title><link>https://bugflation.com/findings/gemini-linux-kernel-review-cve-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/gemini-linux-kernel-review-cve-cluster/</guid><description>Linux stable commits explicitly credit Gemini CLI or experimental Gemini 3.1 Pro review agents on four accepted security fixes. - Out-of-bounds access, NULL dereference, infinite loop, and allocation wraparound, severity high, credited systems Google Gemini security review agents (direct).</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>google-gemini-security-review</category><category>direct</category><category>google-gemini-security-review:direct</category></item><item><title>[Finding] Twig 3.26.0 release credits Claude, Anvil Secure, and Claude Mythos</title><link>https://bugflation.com/findings/twig-claude-anvil-mythos-2026-security-release/</link><guid isPermaLink="true">https://bugflation.com/findings/twig-claude-anvil-mythos-2026-security-release/</guid><description>Twig&apos;s 3.26.0 security release includes critical and high advisories credited to Anvil Secure in collaboration with Claude and Anthropic Research, while the release notes also credit Claude Mythos Preview via Project Glasswing. - Template sandbox bypass and PHP code injection, severity critical, credited systems Claude / Anthropic Research (direct).</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] ZeroPath public research adds seven CVEs and one reserved Monaco report</title><link>https://bugflation.com/findings/zeropath-public-cve-backfill/</link><guid isPermaLink="true">https://bugflation.com/findings/zeropath-public-cve-backfill/</guid><description>ZeroPath&apos;s public research identifies seven additional published CVEs across rsync, AutoGPT, Keycloak, OpenClaw, Avahi, E2nest, and Fonoster, plus a reserved and inconsistently described Monaco identifier. - Authorization bypass, session hijacking, RCE, denial-of-service, and local file inclusion, severity critical, credited systems ZeroPath AI SAST (self-reported).</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>zeropath-ai-sast</category><category>self-reported</category><category>zeropath-ai-sast:self-reported</category></item><item><title>[Finding] Atuin public CVE-backed cluster spans sm-crypto, Vault, and PostgreSQL</title><link>https://bugflation.com/findings/atuin-public-cve-backed-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/atuin-public-cve-backed-cluster/</guid><description>Public advisories credit Tencent Xuanwu Lab&apos;s Atuin Automated Vulnerability Discovery Engine on CVEs in sm-crypto, HashiCorp Vault, and PostgreSQL. - Cryptographic signature malleability, denial of service, and symlink following, severity high, credited systems Atuin Automated Vulnerability Discovery Engine (direct).</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>atuin</category><category>direct</category><category>atuin:direct</category></item><item><title>[Finding] PostgreSQL credits Calif.io and Claude for SSL/GSS recursion DoS</title><link>https://bugflation.com/findings/postgresql-claude-ssl-gss-cve-2026-6479/</link><guid isPermaLink="true">https://bugflation.com/findings/postgresql-claude-ssl-gss-cve-2026-6479/</guid><description>PostgreSQL&apos;s May 2026 security release credits Calif.io in collaboration with Claude and Anthropic Research for CVE-2026-6479, an SSL/GSS initialization recursion denial of service. - SSL/GSS initialization recursion denial of service, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] PostgreSQL May 2026 release credits Xint Code on two CVEs</title><link>https://bugflation.com/findings/postgresql-xint-code-may-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/postgresql-xint-code-may-2026-cluster/</guid><description>PostgreSQL&apos;s May 14, 2026 release credits Xint Code for a high-severity allocation-size issue and a timeofday() memory disclosure. - Server memory corruption and memory disclosure, severity high, credited systems Xint Code (direct).</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>xint-code</category><category>direct</category><category>xint-code:direct</category></item><item><title>[Finding] DepthFirst autonomously finds NGINX Rift and three companion CVEs</title><link>https://bugflation.com/findings/cve-2026-42945-nginx-rift-depthfirst/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-42945-nginx-rift-depthfirst/</guid><description>DepthFirst says its autonomous low-level analysis platform found four confirmed NGINX memory-corruption issues, led by CVE-2026-42945, the critical NGINX Rift rewrite-module heap overflow. - NGINX memory-corruption cluster led by rewrite-module heap overflow RCE, severity critical, credited systems DepthFirst (self-reported).</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>depthfirst</category><category>self-reported</category><category>depthfirst:self-reported</category></item><item><title>[Finding] Fragnesia: V12-assisted Linux kernel page-cache LPE CVE-2026-46300</title><link>https://bugflation.com/findings/cve-2026-46300-fragnesia-v12-linux-kernel/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-46300-fragnesia-v12-linux-kernel/</guid><description>V12&apos;s public PoC and write-up say Fragnesia, CVE-2026-46300, was discovered with V12 by William Bowling and the V12 team; distro trackers and kernel patch mail corroborate the Linux XFRM ESP-in-TCP local-root vulnerability. - Shared page-fragment marker loss leading to page-cache corruption and local privilege escalation, severity high, credited systems V12 (direct).</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>v12</category><category>direct</category><category>v12:direct</category></item><item><title>[Finding] Palo Alto Networks reports 26-CVE frontier-AI scan wave</title><link>https://bugflation.com/findings/palo-alto-frontier-ai-may-2026-cve-wave/</link><guid isPermaLink="true">https://bugflation.com/findings/palo-alto-frontier-ai-may-2026-cve-wave/</guid><description>Palo Alto Networks says its May 2026 Patch Wednesday wave covered 26 CVEs representing 75 issues after scanning more than 130 products with frontier AI models, including Anthropic Mythos, Claude Opus 4.7, and OpenAI GPT-5.5-Cyber. - Vendor-scale frontier-AI vulnerability-discovery wave across PAN-OS, GlobalProtect, Prisma, Cortex, WildFire, Browser, and related products, severity high, credited systems Palo Alto frontier AI scan (self-reported).</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>palo-alto-frontier-ai-scan</category><category>self-reported</category><category>palo-alto-frontier-ai-scan:self-reported</category></item><item><title>[Finding] MDASH and Claude share public credit on HTTP.sys denial of service</title><link>https://bugflation.com/findings/cve-2026-33096-httpsys-mdash-claude/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-33096-httpsys-mdash-claude/</guid><description>CVE-2026-33096 belongs to Microsoft&apos;s MDASH May cohort, while MSRC separately credits Calif.io researchers working with Claude. - HTTP.sys denial of service, severity medium, credited systems Microsoft MDASH (direct), Claude / Anthropic Research (direct).</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>microsoft-mdash</category><category>direct</category><category>microsoft-mdash:direct</category><category>claude-anthropic-research</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Microsoft MDASH publishes 15-CVE Windows networking cohort</title><link>https://bugflation.com/findings/microsoft-mdash-may-2026-windows-cve-cohort/</link><guid isPermaLink="true">https://bugflation.com/findings/microsoft-mdash-may-2026-windows-cve-cohort/</guid><description>Microsoft says its multi-model agentic scanning harness, codename MDASH, helped researchers find a Windows networking and authentication cohort including four Critical remote code execution flaws. - Windows network-stack and authentication vulnerability-discovery cluster, severity critical, credited systems Microsoft MDASH (direct).</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>microsoft-mdash</category><category>direct</category><category>microsoft-mdash:direct</category></item><item><title>[Finding] XBOW reports unauthenticated Exim RCE in Dead.Letter disclosure</title><link>https://bugflation.com/findings/xbow-exim-dead-letter-cve-2026-45185/</link><guid isPermaLink="true">https://bugflation.com/findings/xbow-exim-dead-letter-cve-2026-45185/</guid><description>XBOW says it discovered CVE-2026-45185, a critical unauthenticated Exim remote-code-execution vulnerability in the GnuTLS BDAT path, and Exim/Ubuntu/CVE records corroborate the public issue. - GnuTLS BDAT use-after-free remote code execution, severity critical, credited systems XBOW (self-reported).</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>xbow</category><category>self-reported</category><category>xbow:self-reported</category></item><item><title>[Finding] Apple May 2026 advisories credit Claude-assisted kernel and WebKit reports</title><link>https://bugflation.com/findings/apple-claude-may-2026-security-wave/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-claude-may-2026-security-wave/</guid><description>Apple&apos;s May 2026 security advisories credit Calif.io and Anthropic researchers working with Claude for a kernel root-privilege issue and a WebKit issue. - Kernel privilege escalation and WebKit browser vulnerability, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Apple credits Xint Code on two May 2026 kernel CVEs</title><link>https://bugflation.com/findings/apple-xint-code-may-2026-kernel-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-xint-code-may-2026-kernel-cluster/</guid><description>Apple&apos;s May 2026 advisories credit Ryan Hileman via Xint Code on two kernel vulnerabilities involving unexpected system termination and kernel-state leakage. - Kernel race condition and information leakage, severity medium, credited systems Xint Code (direct).</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>xint-code</category><category>direct</category><category>xint-code:direct</category></item><item><title>DirtyFrag and Copy Fail2 Show the Page-Cache Bug Class Is Not Done</title><link>https://bugflation.com/articles/dirtyfrag-copyfail2-page-cache-bug-class/</link><guid isPermaLink="true">https://bugflation.com/articles/dirtyfrag-copyfail2-page-cache-bug-class/</guid><description>DirtyFrag and Copy Fail2 are not new AI-attributed findings, but they are important CopyFail-adjacent evidence: Linux still has dangerous seams where zero-copy networking, page-cache provenance, and in-place crypto meet.</description><pubDate>Fri, 08 May 2026 06:45:00 GMT</pubDate><category>linux</category><category>copyfail</category><category>dirtyfrag</category><category>page-cache</category><category>analysis</category><author>Mounir Idrassi</author></item><item><title>The Public Record Is Thin, but Real</title><link>https://bugflation.com/articles/public-record-is-thin-but-real/</link><guid isPermaLink="true">https://bugflation.com/articles/public-record-is-thin-but-real/</guid><description>The AI vulnerability-discovery record is still small, but direct credits now span browsers, kernels, bootloaders, crypto libraries, and OSS tooling.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><category>methodology</category><category>evidence</category><author>Bugflation Editorial</author></item><item><title>[Finding] Bynario AI assists Linux CAN raw socket UAF fix</title><link>https://bugflation.com/findings/cve-2026-31532-linux-can-bynario/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-31532-linux-can-bynario/</guid><description>Bynario says its LLM-driven pipeline discovered, validated, and patched CVE-2026-31532, a Linux kernel CAN raw socket use-after-free; the upstream Linux commit includes Assisted-by: Bynario AI. - RCU teardown race causing use-after-free of per-CPU CAN raw socket state, severity high, credited systems BynarIO AI (direct).</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>bynario-ai</category><category>direct</category><category>bynario-ai:direct</category></item><item><title>[Finding] ZeroPath finds Apache NiFi Execute Code permission bypass CVE-2026-39816</title><link>https://bugflation.com/findings/cve-2026-39816-apache-nifi-zeropath/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-39816-apache-nifi-zeropath/</guid><description>ZeroPath Research disclosed an Apache NiFi authorization flaw where users without EXECUTE_CODE can run code through TinkerpopClientService when optional graph extensions are installed. - Authorization bypass leading to server-side code execution, severity high, credited systems ZeroPath AI SAST (self-reported).</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>self-reported</category><category>zeropath-ai-sast:self-reported</category></item><item><title>[Finding] GitHub Taskflow Agent produces 24 public CVEs across thirteen projects</title><link>https://bugflation.com/findings/github-taskflow-cve-backed-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/github-taskflow-cve-backed-cluster/</guid><description>GitHub Security Lab&apos;s AI-powered Taskflow campaigns yielded 24 unique CVEs after human reproduction and triage across thirteen web applications and frameworks. - Authorization bypass, data exposure, XSS, CSRF, and business-logic vulnerabilities, severity high, credited systems GitHub Security Lab Taskflow Agent (direct).</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>github-security-lab-taskflow</category><category>direct</category><category>github-security-lab-taskflow:direct</category></item><item><title>CopyFail Is the Bugflation Moment</title><link>https://bugflation.com/articles/copyfail-is-the-bugflation-moment/</link><guid isPermaLink="true">https://bugflation.com/articles/copyfail-is-the-bugflation-moment/</guid><description>CVE-2026-31431 shows the bugflation pattern: expert framing plus AI-assisted subsystem review made a kernel root bug cheap to surface.</description><pubDate>Mon, 04 May 2026 12:00:00 GMT</pubDate><category>copyfail</category><category>linux</category><category>xint-code</category><category>thesis</category><author>Mounir Idrassi</author></item><item><title>Introducing Bugflation</title><link>https://bugflation.com/articles/introducing-bugflation/</link><guid isPermaLink="true">https://bugflation.com/articles/introducing-bugflation/</guid><description>Bugflation names the gap between AI-accelerated vulnerability discovery and the slower systems that validate, patch, and deploy fixes.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>editorial</category><category>thesis</category><author>Mounir Idrassi</author></item><item><title>Second-Pass Audit: What Changed in the Ledger</title><link>https://bugflation.com/articles/second-pass-audit-what-changed/</link><guid isPermaLink="true">https://bugflation.com/articles/second-pass-audit-what-changed/</guid><description>The launch audit added AI-attributed disclosures from Security Copilot, Claude, OpenAI Codex Security, AISLE, OSS-Fuzz AI, and Calif.io.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>audit</category><category>evidence</category><author>Bugflation Editorial</author></item><item><title>[Finding] Striga says its Apache httpd scan surfaced CVE-2026-23918</title><link>https://bugflation.com/findings/cve-2026-23918-apache-httpd-striga/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-23918-apache-httpd-striga/</guid><description>Striga says an open-weights model scan costing under $100 surfaced the Apache HTTP Server 2.4.66 mod_http2 double-free behind CVE-2026-23918; Apache credits Bartlomiej Dmitruk, striga.ai, and Stanislaw Strzalkowski, isec.pl, as finders. - HTTP/2 double free with possible remote code execution, severity high, credited systems Striga AI (self-reported).</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>striga-ai</category><category>self-reported</category><category>striga-ai:self-reported</category></item><item><title>Patch Capacity Is the Bottleneck</title><link>https://bugflation.com/articles/patch-capacity-is-the-bottleneck/</link><guid isPermaLink="true">https://bugflation.com/articles/patch-capacity-is-the-bottleneck/</guid><description>If AI makes discovery cheaper, the scarce resource moves downstream: triage, reproduction, patch review, release engineering, and deployment.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate><category>operations</category><category>defense</category><author>Bugflation Editorial</author></item><item><title>From Big Sleep to XBOW: Two Different Signals</title><link>https://bugflation.com/articles/from-big-sleep-to-xbow/</link><guid isPermaLink="true">https://bugflation.com/articles/from-big-sleep-to-xbow/</guid><description>Big Sleep and XBOW point to different parts of the AI security stack: source-aware vulnerability research and autonomous black-box testing.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>big-sleep</category><category>xbow</category><category>analysis</category><author>Bugflation Editorial</author></item><item><title>[Finding] Bynario AI assists Linux FUSE page-cache overflow fix</title><link>https://bugflation.com/findings/cve-2026-31694-linux-fuse-bynario/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-31694-linux-fuse-bynario/</guid><description>The Linux fix for CVE-2026-31694, a FUSE readdir page-cache overflow, includes Assisted-by: Bynario AI; Bynario says its LLM-driven pipeline found and validated the FUSE bug, while the upstream commit also carries separate reporter credits. - Oversized FUSE dirent copied into a single page-cache page, severity high, credited systems BynarIO AI (direct).</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>bynario-ai</category><category>direct</category><category>bynario-ai:direct</category></item><item><title>[Finding] AISLE analyzer finds Elastic Beats denial-of-service cluster</title><link>https://bugflation.com/findings/aisle-elastic-beats-dos-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/aisle-elastic-beats-dos-cluster/</guid><description>AISLE says its analyzer discovered nine Elastic Beats denial-of-service vulnerabilities across Packetbeat, Filebeat, and Metricbeat, with several CVEs already public and fixed. - Network and telemetry parser denial-of-service vulnerabilities, severity medium, credited systems AISLE (self-reported).</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category></item><item><title>[Finding] AISLE finds FreeBSD dhclient root RCE and two companion core CVEs</title><link>https://bugflation.com/findings/aisle-freebsd-april-2026-dhclient-libnv-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/aisle-freebsd-april-2026-dhclient-libnv-cluster/</guid><description>FreeBSD&apos;s April 29, 2026 advisories credit Joshua Rogers of AISLE Research Team for CVE-2026-42511, a local-network-to-root dhclient RCE, plus a second dhclient heap overflow and a libnv stack overflow. - DHCP client command injection, heap overflow, and libnv stack overflow, severity high, credited systems AISLE (self-reported).</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category></item><item><title>[Finding] CopyFail: Linux kernel page-cache write to root found with Xint Code</title><link>https://bugflation.com/findings/cve-2026-31431-copyfail-linux-kernel/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-31431-copyfail-linux-kernel/</guid><description>CVE-2026-31431 is a Linux kernel AF_ALG/authencesn logic bug that gives an unprivileged local user a controlled 4-byte page-cache write and a reliable path to root on affected systems. - Incorrect resource transfer -&gt; page-cache corruption -&gt; local privilege escalation, severity high, credited systems Xint Code (direct).</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>xint-code</category><category>direct</category><category>xint-code:direct</category></item><item><title>[Finding] Xint public tracker adds seven CVE-backed findings beyond CopyFail</title><link>https://bugflation.com/findings/xint-code-public-tracker-cve-backed-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/xint-code-public-tracker-cve-backed-cluster/</guid><description>Theori&apos;s Xint public bug tracker lists 50 Xint tracker findings as of May 5, 2026; seven non-CopyFail entries have CVE IDs across CPython, CUPS, NGINX, mruby, MariaDB, and PostgreSQL. - Memory-safety and parser vulnerabilities across open-source server and runtime projects, severity critical, credited systems Xint Code (self-reported).</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>xint-code</category><category>self-reported</category><category>xint-code:self-reported</category></item><item><title>[Finding] ZeroPath finds ProFTPD mod_sql CVE-2026-42167</title><link>https://bugflation.com/findings/cve-2026-42167-proftpd-zeropath/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-42167-proftpd-zeropath/</guid><description>ZeroPath Research disclosed a ProFTPD mod_sql SQL injection that can lead to authentication bypass, privilege escalation, credential exfiltration, or RCE depending on configuration; ProFTPD fixed it in 1.3.9a. - SQL injection in FTP SQL logging and authentication paths, severity high, credited systems ZeroPath AI SAST (self-reported).</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>self-reported</category><category>zeropath-ai-sast:self-reported</category></item><item><title>[Finding] AISLE autonomous analyzer finds a 20-CVE OpenSSL run</title><link>https://bugflation.com/findings/aisle-openssl-2025-2026-cve-run/</link><guid isPermaLink="true">https://bugflation.com/findings/aisle-openssl-2025-2026-cve-run/</guid><description>AISLE reports 20 OpenSSL CVEs across three coordinated releases, including all 12 January 2026 OpenSSL CVEs and five of seven April 2026 CVEs. - Cryptographic-library vulnerability cluster, severity high, credited systems AISLE (self-reported).</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category></item><item><title>[Finding] FreeBSD April kernel follow-ups credited to Nicholas Carlini using Claude</title><link>https://bugflation.com/findings/freebsd-april-2026-claude-followups/</link><guid isPermaLink="true">https://bugflation.com/findings/freebsd-april-2026-claude-followups/</guid><description>FreeBSD-SA-26:10.tty and FreeBSD-SA-26:11.amd64 credit Nicholas Carlini using Claude, Anthropic for two additional kernel security advisories after CVE-2026-4747. - Kernel use-after-free and memory-protection logic flaws, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Libgcrypt credits Claude-assisted Calif.io report for Dilithium bounds check</title><link>https://bugflation.com/findings/libgcrypt-claude-dilithium-cve-2026-41990/</link><guid isPermaLink="true">https://bugflation.com/findings/libgcrypt-claude-dilithium-cve-2026-41990/</guid><description>The GnuPG Libgcrypt 1.12.2 security release credits Calif.io in collaboration with Claude and Anthropic Research for CVE-2026-41990, a missing bounds check in Dilithium context handling. - Post-quantum signature context bounds check, severity medium, credited systems Claude / Anthropic Research (direct).</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Firefox 150 ships fixes for 271 Mythos-identified vulnerabilities</title><link>https://bugflation.com/findings/mozilla-firefox-150-mythos-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/mozilla-firefox-150-mythos-cluster/</guid><description>Mozilla says Firefox 150 includes fixes for 271 vulnerabilities identified during an initial Claude Mythos Preview evaluation; public CVE advisories include direct Claude credit on specific entries. - Browser vulnerability cluster, severity high, credited systems Claude Mythos Preview (direct).</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-mythos</category><category>direct</category><category>claude-mythos:direct</category></item><item><title>[Finding] ZeroPath discloses two critical Spinnaker RCE CVEs</title><link>https://bugflation.com/findings/zeropath-spinnaker-rce-cve-2026-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/zeropath-spinnaker-rce-cve-2026-cluster/</guid><description>ZeroPath Research says it found two critical Spinnaker RCEs, CVE-2026-32604 and CVE-2026-32613, in Clouddriver and Echo; GitHub advisories rate both 9.9 critical and Spinnaker shipped fixes. - Command injection and Spring Expression Language code injection in deployment services, severity critical, credited systems ZeroPath AI SAST (self-reported).</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>zeropath-ai-sast</category><category>self-reported</category><category>zeropath-ai-sast:self-reported</category></item><item><title>[Finding] Microsoft credits Atuin on Windows AFD Winsock elevation of privilege</title><link>https://bugflation.com/findings/cve-2026-26168-windows-atuin/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-26168-windows-atuin/</guid><description>Microsoft&apos;s April 2026 advisory directly names Tencent Xuanwu Lab&apos;s Atuin Automated Vulnerability Discovery System among the reporters of a Windows AFD Winsock EoP. - Kernel elevation of privilege, severity high, credited systems Atuin Automated Vulnerability Discovery Engine (direct).</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>atuin</category><category>direct</category><category>atuin:direct</category></item><item><title>[Finding] Calif.io MADBugs credits Claude on NGINX and wolfSSL findings</title><link>https://bugflation.com/findings/califio-claude-nginx-wolfssl-madbugs/</link><guid isPermaLink="true">https://bugflation.com/findings/califio-claude-nginx-wolfssl-madbugs/</guid><description>Calif.io&apos;s MADBugs work with Claude and Anthropic Research produced a high-severity NGINX DAV issue and a wolfSSL release cluster credited to Calif.io in collaboration with Claude and Anthropic Research. - Web server and cryptographic-library vulnerability cluster, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] FreeBSD NFS remote kernel RCE identified and exploited by Claude Mythos Preview</title><link>https://bugflation.com/findings/cve-2026-4747-freebsd-mythos-nfs-rce/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-4747-freebsd-mythos-nfs-rce/</guid><description>CVE-2026-4747 is a 17-year-old FreeBSD RPCSEC_GSS/NFS kernel RCE that Anthropic says Claude Mythos Preview fully autonomously identified and exploited. - Remote kernel memory corruption -&gt; root code execution, severity critical, credited systems Claude Mythos Preview (direct).</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>claude-mythos</category><category>direct</category><category>claude-mythos:direct</category></item><item><title>[Finding] Claude-assisted review finds Apache ActiveMQ Jolokia RCE CVE-2026-34197</title><link>https://bugflation.com/findings/cve-2026-34197-activemq-claude/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-34197-activemq-claude/</guid><description>Horizon3.ai says Claude took the first pass on the source-code review that led to CVE-2026-34197, an Apache ActiveMQ Jolokia/JMX code-execution issue later accepted by Apache and added to CISA KEV. - Jolokia/JMX code execution through network connector configuration, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Mozilla Firefox 148 and 149 advisories credit Claude-assisted research</title><link>https://bugflation.com/findings/claude-firefox-148-149-cve-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/claude-firefox-148-149-cve-cluster/</guid><description>Anthropic says Claude Opus 4.6 found 22 Firefox vulnerabilities in two weeks; Mozilla advisories for Firefox 148 and 149 publicly credit researchers using Claude from Anthropic across 28 CVEs. - Browser memory-safety and sandbox-relevant vulnerability cluster, severity high, credited systems Claude / Anthropic Research (direct).</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>claude-anthropic-research</category><category>direct</category><category>claude-anthropic-research:direct</category></item><item><title>[Finding] Microsoft Bing Images OS command injection credited by XBOW</title><link>https://bugflation.com/findings/cve-2026-32191-bing-images-command-injection/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-32191-bing-images-command-injection/</guid><description>CVE-2026-32191 is a critical Bing Images remote-code-execution issue that XBOW lists among autonomous findings in Microsoft software. - OS command injection -&gt; remote code execution, severity critical, credited systems XBOW (self-reported).</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>xbow</category><category>self-reported</category><category>xbow:self-reported</category></item><item><title>[Finding] Microsoft Bing Images command injection credited by XBOW</title><link>https://bugflation.com/findings/cve-2026-32194-bing-images-command-injection/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-32194-bing-images-command-injection/</guid><description>CVE-2026-32194 is a critical Bing Images command-injection RCE that XBOW says was found by its autonomous offensive-security system. - Command injection -&gt; remote code execution, severity critical, credited systems XBOW (self-reported).</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>xbow</category><category>self-reported</category><category>xbow:self-reported</category></item><item><title>[Finding] OpenAI Codex Security publishes OSS CVE examples</title><link>https://bugflation.com/findings/openai-codex-security-oss-cve-examples/</link><guid isPermaLink="true">https://bugflation.com/findings/openai-codex-security-oss-cve-examples/</guid><description>OpenAI says Codex Security, formerly Aardvark, has produced 14 assigned CVEs in open-source projects and lists examples across GnuTLS, Gogs, Thorium, and GnuPG. - Open-source vulnerability discovery and validation cluster, severity high, credited systems OpenAI Aardvark / Codex Security (direct).</description><pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>openai-aardvark</category><category>direct</category><category>openai-aardvark:direct</category></item><item><title>[Finding] Microsoft Devices Pricing Program critical RCE credited by XBOW</title><link>https://bugflation.com/findings/cve-2026-21536-microsoft-devices-pricing/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2026-21536-microsoft-devices-pricing/</guid><description>XBOW says it was credited for CVE-2026-21536, a critical Microsoft Devices Pricing Program remote-code-execution vulnerability with a 9.8 CVSS v3.1 score. - Remote code execution, severity critical, credited systems XBOW (self-reported).</description><pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>xbow</category><category>self-reported</category><category>xbow:self-reported</category></item><item><title>[Finding] Aether finds a two-part OpenClaw tool-permission escalation</title><link>https://bugflation.com/findings/aether-openclaw-tool-escalation/</link><guid isPermaLink="true">https://bugflation.com/findings/aether-openclaw-tool-escalation/</guid><description>OpenClaw&apos;s HTTP gateway exposed high-risk session tools while ACP clients could auto-approve risky permissions, expanding a stolen gateway token into session control and possible command execution. - Improper tool authorization and unsafe permission auto-approval, severity high, credited systems Aether AI (direct).</description><pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>aether-ai</category><category>direct</category><category>aether-ai:direct</category></item><item><title>[Finding] Endor Labs AI SAST finds SSRF in OpenClaw&apos;s Image tool</title><link>https://bugflation.com/findings/endor-openclaw-image-tool-ssrf/</link><guid isPermaLink="true">https://bugflation.com/findings/endor-openclaw-image-tool-ssrf/</guid><description>An AI-assisted dataflow review found that remote image URLs bypassed OpenClaw&apos;s SSRF guard, allowing requests to internal and restricted network targets. - Server-side request forgery in remote media fetching, severity high, credited systems Endor Labs AI SAST (direct).</description><pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>endor-ai-sast</category><category>direct</category><category>endor-ai-sast:direct</category></item><item><title>[Finding] Linux records three CVEs discovered by Atuin</title><link>https://bugflation.com/findings/atuin-linux-kernel-cve-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/atuin-linux-kernel-cve-cluster/</guid><description>Public Linux CVE and fix records explicitly name Atuin on memory-safety and crash bugs in USB storage, CH341 SPI, and the applicom driver. - Heap corruption, out-of-bounds access, and NULL dereference, severity high, credited systems Atuin Automated Vulnerability Discovery Engine (direct).</description><pubDate>Tue, 13 Jan 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>atuin</category><category>direct</category><category>atuin:direct</category></item><item><title>[Finding] Linux fixes credit ZeroPath on ksmbd and svcrdma CVEs</title><link>https://bugflation.com/findings/zeropath-linux-kernel-cve-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/zeropath-linux-kernel-cve-cluster/</guid><description>Linux records say ZeroPath found a remotely triggerable ksmbd resource leak and an svcrdma memory-copy offset error. - Remote resource exhaustion and memory-copy boundary error, severity high, credited systems ZeroPath AI SAST (direct).</description><pubDate>Tue, 13 Jan 2026 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>direct</category><category>zeropath-ai-sast:direct</category></item><item><title>[Finding] Apple WebKit 26.2 follow-up issues credited to Google Big Sleep</title><link>https://bugflation.com/findings/apple-webkit-26-2-bigsleep-followups/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-webkit-26-2-bigsleep-followups/</guid><description>Apple&apos;s iOS 26.2 and iPadOS 26.2 security content credits Google Big Sleep on additional WebKit issues, including CVE-2025-43535 and CVE-2025-46299. - WebKit memory handling / internal-state disclosure, severity medium, credited systems Google Big Sleep (direct).</description><pubDate>Fri, 09 Jan 2026 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>google-big-sleep</category><category>direct</category><category>google-big-sleep:direct</category></item><item><title>[Finding] ZeroPath AI SAST reports seven FFmpeg memory-safety fixes</title><link>https://bugflation.com/findings/zeropath-ffmpeg-seven-memory-safety-fixes/</link><guid isPermaLink="true">https://bugflation.com/findings/zeropath-ffmpeg-seven-memory-safety-fixes/</guid><description>ZeroPath says its AI-assisted SAST reported seven FFmpeg memory-safety and protocol-logic bugs, including buffer overflows, invalid frees, and underflow-driven memory disclosure; the public post links to upstream FFmpeg patches. - Memory-safety and protocol logic vulnerability cluster, severity high, credited systems ZeroPath AI SAST (self-reported).</description><pubDate>Tue, 02 Dec 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>self-reported</category><category>zeropath-ai-sast:self-reported</category></item><item><title>[Finding] Chrome directly credits Big Sleep on eleven additional 2025 CVEs</title><link>https://bugflation.com/findings/google-big-sleep-chrome-2025-backfill/</link><guid isPermaLink="true">https://bugflation.com/findings/google-big-sleep-chrome-2025-backfill/</guid><description>Chrome release notes name Google Big Sleep on eleven previously omitted V8 and ANGLE vulnerabilities published from August through November 2025. - Out-of-bounds write, heap overflow, integer overflow, use-after-free, and type confusion, severity high, credited systems Google Big Sleep (direct).</description><pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>google-big-sleep</category><category>direct</category><category>google-big-sleep:direct</category></item><item><title>[Finding] ZeroPath AI Security Engineer credited on sudo exec_mailer fix</title><link>https://bugflation.com/findings/zeropath-sudo-exec-mailer-crackarmor/</link><guid isPermaLink="true">https://bugflation.com/findings/zeropath-sudo-exec-mailer-crackarmor/</guid><description>The sudo project credited the ZeroPath AI Security Engineer for an exec_mailer fix that made privilege-drop failures fatal and dropped group privileges; Qualys later documented the same sudo behavior as part of its CrackArmor AppArmor + Sudo + Postfix root chain. - Incomplete privilege drop in sudo mailer execution, severity high, credited systems ZeroPath AI SAST (direct).</description><pubDate>Sat, 08 Nov 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>direct</category><category>zeropath-ai-sast:direct</category></item><item><title>[Finding] Apple WebKit 26.1 security cluster credited to Google Big Sleep</title><link>https://bugflation.com/findings/apple-webkit-26-1-bigsleep-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/apple-webkit-26-1-bigsleep-cluster/</guid><description>Apple&apos;s Safari 26.1 security content credits Google Big Sleep for five WebKit CVEs spanning buffer overflow, state handling, memory corruption, and use-after-free issues. - WebKit memory-safety cluster, severity high, credited systems Google Big Sleep (direct).</description><pubDate>Mon, 03 Nov 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>google-big-sleep</category><category>direct</category><category>google-big-sleep:direct</category></item><item><title>[Finding] Apple credits BynarIO AI on Model I/O CVE-2025-43377</title><link>https://bugflation.com/findings/cve-2025-43377-apple-modelio-bynario/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-43377-apple-modelio-bynario/</guid><description>Apple&apos;s macOS Sequoia 15.7.2 security content credits BynarIO AI for CVE-2025-43377, a Model I/O out-of-bounds read fixed with improved bounds checking. - Out-of-bounds read in Model I/O media parsing, severity medium, credited systems BynarIO AI (direct).</description><pubDate>Mon, 03 Nov 2025 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>bynario-ai</category><category>direct</category><category>bynario-ai:direct</category></item><item><title>[Finding] Chrome directly credits AISLE Research on 2025 security fix</title><link>https://bugflation.com/findings/cve-2025-12443-chrome-aisle/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-12443-chrome-aisle/</guid><description>Chrome&apos;s October 2025 stable release directly credits AISLE Research on a Medium-severity WebXR out-of-bounds read. - Out-of-bounds read, severity medium, credited systems AISLE (self-reported).</description><pubDate>Tue, 28 Oct 2025 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>aisle</category><category>self-reported</category><category>aisle:self-reported</category></item><item><title>[Finding] ZeroPath scanner finds better-auth API key takeover CVE-2025-61928</title><link>https://bugflation.com/findings/cve-2025-61928-better-auth-zeropath/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-61928-better-auth-zeropath/</guid><description>ZeroPath says its scanner found an authentication-bypass flaw in better-auth&apos;s API keys plugin that allowed unauthenticated attackers to mint or update API keys for arbitrary users. - Authentication bypass in API key creation and update routes, severity high, credited systems ZeroPath AI SAST (self-reported).</description><pubDate>Sun, 19 Oct 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>zeropath-ai-sast</category><category>self-reported</category><category>zeropath-ai-sast:self-reported</category></item><item><title>[Finding] Chrome ANGLE use-after-free reported by Google Big Sleep</title><link>https://bugflation.com/findings/cve-2025-9478-chrome-angle-bigsleep/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-9478-chrome-angle-bigsleep/</guid><description>CVE-2025-9478 is a critical Chrome ANGLE use-after-free reported by Google Big Sleep and fixed in Chrome 139.0.7258.154/.155. - Use-after-free -&gt; heap corruption, severity critical, credited systems Google Big Sleep (direct).</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>google-big-sleep</category><category>direct</category><category>google-big-sleep:direct</category></item><item><title>[Finding] Chrome V8 out-of-bounds write reported by Google Big Sleep</title><link>https://bugflation.com/findings/cve-2025-9132-chrome-v8-oob-write/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-9132-chrome-v8-oob-write/</guid><description>Chrome 139 fixed CVE-2025-9132, a high-severity V8 out-of-bounds write reported by Google Big Sleep. - Out-of-bounds write -&gt; heap corruption, severity high, credited systems Google Big Sleep (direct).</description><pubDate>Tue, 19 Aug 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>google-big-sleep</category><category>direct</category><category>google-big-sleep:direct</category></item><item><title>[Finding] pwn.ai reports unauthenticated root RCE in XSpeeder SXZOS</title><link>https://bugflation.com/findings/cve-2025-54322-xspeeder-pwn-ai/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-54322-xspeeder-pwn-ai/</guid><description>pwn.ai says its autonomous platform found an unauthenticated command-injection path yielding root execution in XSpeeder SXZOS; the public CVE record corroborates the vulnerability. - Unauthenticated OS command injection and root code execution, severity critical, credited systems pwn.ai (self-reported).</description><pubDate>Tue, 22 Jul 2025 00:00:00 GMT</pubDate><category>finding</category><category>critical</category><category>pwn-ai</category><category>self-reported</category><category>pwn-ai:self-reported</category></item><item><title>[Finding] SQLite aggregate-term memory corruption found by Big Sleep</title><link>https://bugflation.com/findings/cve-2025-6965-sqlite-aggregate-terms/</link><guid isPermaLink="true">https://bugflation.com/findings/cve-2025-6965-sqlite-aggregate-terms/</guid><description>CVE-2025-6965 affected SQLite before 3.50.2 and was publicly described by Google as a Big Sleep finding that helped cut off imminent exploitation. - Aggregate-term accounting -&gt; memory corruption, severity high, credited systems Google Big Sleep (direct).</description><pubDate>Tue, 15 Jul 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>google-big-sleep</category><category>direct</category><category>google-big-sleep:direct</category></item><item><title>[Finding] Microsoft Security Copilot accelerates GRUB2, U-Boot, and Barebox findings</title><link>https://bugflation.com/findings/microsoft-security-copilot-bootloader-cluster/</link><guid isPermaLink="true">https://bugflation.com/findings/microsoft-security-copilot-bootloader-cluster/</guid><description>Microsoft says Security Copilot helped uncover 20 bootloader CVEs spanning GRUB2, U-Boot, and Barebox, including Secure Boot bypass-relevant GRUB2 memory-corruption flaws. - Bootloader memory corruption and Secure Boot bypass-relevant flaws, severity high, credited systems Microsoft Security Copilot (direct).</description><pubDate>Mon, 31 Mar 2025 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>microsoft-security-copilot</category><category>direct</category><category>microsoft-security-copilot:direct</category></item><item><title>[Finding] Google OSS-Fuzz AI finds OpenSSL CVE-2024-9143</title><link>https://bugflation.com/findings/google-oss-fuzz-ai-openssl-cve-2024-9143/</link><guid isPermaLink="true">https://bugflation.com/findings/google-oss-fuzz-ai-openssl-cve-2024-9143/</guid><description>Google says its LLM-generated and enhanced OSS-Fuzz targets found 26 new vulnerabilities, highlighted by CVE-2024-9143 in OpenSSL. - AI-generated fuzz target vulnerability discovery, severity medium, credited systems Google OSS-Fuzz AI (direct).</description><pubDate>Wed, 20 Nov 2024 00:00:00 GMT</pubDate><category>finding</category><category>medium</category><category>google-oss-fuzz-ai</category><category>direct</category><category>google-oss-fuzz-ai:direct</category></item><item><title>[Finding] Big Sleep finds an exploitable SQLite stack buffer underflow before release</title><link>https://bugflation.com/findings/google-bigsleep-sqlite-stack-underflow/</link><guid isPermaLink="true">https://bugflation.com/findings/google-bigsleep-sqlite-stack-underflow/</guid><description>Google Project Zero and DeepMind reported Big Sleep&apos;s first public real-world finding: an exploitable SQLite memory-safety issue fixed before reaching an official release. - Stack buffer underflow, severity high, credited systems Google Big Sleep (direct).</description><pubDate>Fri, 01 Nov 2024 00:00:00 GMT</pubDate><category>finding</category><category>high</category><category>google-big-sleep</category><category>direct</category><category>google-big-sleep:direct</category></item></channel></rss>