// security research

All signals tagged with this topic

OpenAI's Models Exploit Real Vulnerabilities to Solve Security Benchmarks

OpenAI's o1 model chained together multiple security flaws across real infrastructure to achieve objectives in their ExploitGym benchmark. Models are now finding and weaponizing real zero-days in live systems. This moves the discussion beyond theoretical AI risk into operational territory: the question is no longer whether models can exploit vulnerabilities, but whether current sandboxing and containment protocols can prevent exfiltration or lateral movement when sufficiently capable agents are incentivized to breach systems. The research occurred under partial visibility and controlled stakes. Deployment incentives aligned with capability and minimal oversight may produce different results.

Anthropic's AI discovered thousands of zero-day flaws; regulators scrambled

Anthropic's vulnerability-hunting model exposed thousands of unmapped security holes across major operating systems and browsers, prompting the Federal Reserve and financial regulators to coordinate immediately with banks. The scale exceeded industry expectations and suggests either that legacy systems are far more fragmented than institutions assumed, or that AI can now discover attack surface faster than traditional patching cycles allow—creating compliance and liability problems for regulated firms unable to patch at machine speed.