InfoNews
3 lessons from frontier AI vulnerability research
- Published
- Record updated
Summary
Microsoft's FORGE Lab reports that from May 2026 through September 2026 its agentic discovery work helped find Windows vulnerabilities assigned 140 CVEs, 52 of them addressed in the September 2026 security release. Its 155 internally validated reports span 23 open-source projects, including the Linux kernel, and one Linux report became the first Akrites submission to result in a patch merged into the Linux kernel. The post argues that discovery only creates security value when validation and remediation can keep pace.
Related items
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review
- HighGHSA-h4xc-3qfq-jf93: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpointSame vendor · GitHub Advisory Database
- InfoMicrosoft Teams to get support for third-party deepfake detection toolsSame vendor · BleepingComputer