← heapsort-ai

cybersecurity

132 items

ARTICLEDEV.to AI·4/8/2026

The OpenClaw Security Crisis: 135,000 Exposed AI Agents and the Runtime Governance Gap

Em 3 de fevereiro de 2026, uma grave vulnerabilidade (CVE-2026-25253, CVSS 8.8) foi divulgada no OpenClaw, um agente de IA de código aberto, permitindo execução remota de código. Isso levou à descoberta de 138 vulnerabilidades em 63 dias, com mais de 135.000 instâncias de OpenClaw publicamente expostas globalmente, muitas sem autenticação.

28
NEWSDEV.to AI·27d ago

Elastic Security MCP App: Interactive security operations inside your AI Tools

Elastic has launched the Security MCP App, an extension for the Model Context Protocol that embeds interactive security operations like alert triage and threat hunting directly into AI assistants. This tool provides visual dashboards within AI conversations, enabling SOC analysts to perform investigations and actions that synchronize in real-time with Elasticsearch and Kibana, reducing context switching.

28
ARTICLEDEV.to AI·24d ago

MCP Security is Broken — So I Built a Scanner

The Model Context Protocol (MCP), a new standard for connecting AI agents to tools, is currently experiencing severe security flaws. A scan found that 36.7% of over 7,000 live MCP servers were vulnerable to SSRF, with hundreds lacking authentication or encryption. To address this, the AgentWarden CLI tool has been developed to scan MCP servers for real vulnerabilities.

28
ARTICLEDEV.to AI·4/22/2026

AI Could Never Fully Take Over Cybersecurity

AI has profoundly transformed cybersecurity with its speed and data analysis, yet it cannot fully take over due to its reliance on past patterns and inability to handle novel, human-driven threats. Human professionals provide essential intuition and critical thinking for unpredictable attack strategies that AI struggles to identify.

27
RESEARCHarXiv CS.CL·4/17/2026

Hierarchical Retrieval Augmented Generation for Adversarial Technique Annotation in Cyber Threat Intelligence Text

This paper introduces H-TechniqueRAG, a novel hierarchical Retrieval-Augmented Generation (RAG) framework designed to improve the annotation of adversarial techniques in Cyber Threat Intelligence (CTI) text. It addresses the limitation of flat RAG approaches by incorporating the inherent tactic-technique taxonomy of the MITRE ATT&CK framework through a two-stage retrieval mechanism.

27
ARTICLEDEV.to AI·4/16/2026

Complete Guide to AI-Powered Zero-Day Vulnerability Discovery — Claude Opus 4.6's 500+ Zero-Days and the Security Paradigm Shift

This article analyzes how Claude Opus 4.6 discovered over 500 zero-day vulnerabilities, including a 23-year-old Linux kernel bug, transforming LLMs into autonomous security research agents. It explores the technical mechanisms and DevSecOps implications of this AI-driven vulnerability discovery.

27
ARTICLEDEV.to AI·4/10/2026

Inside Anthropic's Project Glasswing: The AI Model That Found Zero-Days in Every Major OS

Em 7 de abril de 2026, a Anthropic anunciou o Project Glasswing, apresentando o modelo de IA Claude Mythos Preview, capaz de identificar milhares de vulnerabilidades zero-day em todos os principais sistemas operacionais e navegadores. Este modelo de fronteira demonstrou ser superior à detecção humana e automatizada, com profundas implicações para a cibersegurança.

27