Vulnerabilities are weaknesses or flaws in systems, software, hardware, configurations, or processes that adversaries can exploit to compromise confidentiality, integrity, or availability. The concept underpins vulnerability management, regulatory compliance, risk assessment, and security investment decisions across enterprise IT, cloud, and operational technology environments.
A local privilege escalation flaw in Linux kernel versions 4.17+ can let an unprivileged user gain root access. The issue, CVE-2026-31431 (“Copy Fail”), involves algif_aead/AF_ALG page-cache writes and targets in-memory setuid binaries.
Ollama’s model quantization engine has an unauthenticated remote information disclosure flaw in CVE-2026-5757 that can let an attacker with model upload access read and exfiltrate server heap memory.
Aqua Security introduced Aqua Compass, an MCP server in runtime security workflows, and new runtime risk dashboards that recalculate monetary exposure as controls enforce.
Endor Labs launched an agentic code security benchmark extending Carnegie Mellon’s SusVibes, plus a public leaderboard (Agent Security League). The benchmark tests AI coding agents on 200 real-world tasks across 108 open-source projects and 77 CWE classes, including anti-cheating safeguards. Results compare functional correctness and security outcomes across agent/model pairs.
The discovery clock just accelerated On April 7, Anthropic announced that its newest model, Claude Mythos Preview, had autonomously discovered thousands of high and critical severity zero-day vulnerabilities across every major operating system and web browser—many hiding in plain sight for over a decade. A 27-year-old bug in OpenBSD. A 16-year-old flaw in FFmpeg that
The post When AI Finds Every Bug appeared first on NSS Labs.