Full Archive · Page 11

Research archive, page 11

Browse entries 241–264 of 1531. Return to the first page to search and filter the complete collection.

The Hacker News AI Security August 20, 2026 news

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

A joint U.S. government advisory describes threat actors using AI-assisted Python scripts and public automation libraries to find and interact with exposed Siemens S7 and other PLCs. The activity relies on known vulnerabilities and weak segmentation for reconnaissance, credential access, denial of service, and capability development rather than a novel model-specific exploit.

The Hacker News AI Security August 5, 2026 news

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Paperclip vulnerabilities let malicious agent imports reach host command execution through an authorization gap in network deployments and DNS rebinding against local-trusted deployments; additional routes missed expected access checks. The reviewed code in v2026.416.0 contains the import and hostname-validation fixes, although public advisory metadata was not fully aligned and no in-the-wild exploitation was reported.

The Hacker News AI Security August 4, 2026 news

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Pillar Security showed that a public GitHub issue could prompt-inject an ADK triage agent into invoking a privileged code-fixing workflow. Proofs of concept achieved CI-runner code execution and exposed bot and cloud credentials; Google removed three workflows, with no public evidence of in-the-wild exploitation.

The Hacker News AI Security August 3, 2026 news

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

Three trust_remote_code bypasses in Hugging Face Diffusers let a crafted model repository execute Python during pipeline loading, including cross-repository, local-snapshot, and time-of-check/time-of-use paths. The affected cases are tracked as CVE-2026-44513, CVE-2026-44827, and CVE-2026-45804; Diffusers 0.38.0 contains the fixes.

METR February 18, 2026 analysis

Protecting confidential model evaluations: visible labels and technical access boundaries

METR’s February account describes confidentiality levels, project-specific access, codenames and practice handling sensitive questions. Technical measures include centrally managed membership, restrictions on external sharing, device controls and authorization for model transcripts. The useful distinction is between norms that reduce conversational slips and controls that restrict access. This is a dated description of METR’s own arrangements, not an independent audit or proof that those measures prevent every breach.

Frontend verification: combine deterministic replay with explicit review of visible changes video thumbnail Play video
AI Engineer October 2, 2026 video

Frontend verification: combine deterministic replay with explicit review of visible changes

Gabriel Spencer-Harper explains a frontend review workflow that records non-production sessions, replays them before and after a change, and presents screenshot differences for judgment. Recorded network responses and browser scheduling controls reduce incidental variation, while executed-line coverage guides session selection. The method can expose visible regressions in recorded states, but coverage does not establish correctness of every state or nonvisual behavior. Claims of exhaustive verification and superiority to other test tools are not established by the demonstrated examples.

Coding-agent maintenance: preserve decisions and enforce the actual action boundary video thumbnail Play video
AI Engineer September 27, 2026 video

Coding-agent maintenance: preserve decisions and enforce the actual action boundary

Andrew Orobator’s publisher notes describe a feature-flag cleanup workflow that screens code complexity and experiment state before asking a coding agent to generate a patch. Skills preserve recurring decisions, work logs carry session history, and CI supplies evidence for human review. His safeguard example shows why a commit hook can miss a separate file-writing path and why an agent must not invent its own bypass exception. Seven reported green-CI pull requests demonstrate a small screened workflow, not general reliability.

Software Engineering Is Becoming Factory Engineering — Zach Lloyd, Warp video thumbnail Play video
AI Engineer September 27, 2026 video

Software Engineering Is Becoming Factory Engineering — Zach Lloyd, Warp

Zach Lloyd describes a software-development loop connecting issue triage, specifications, implementation, review, verification and production monitoring. Human corrections can become inputs to revised agent skills, while product judgment determines which work is worth building. The presentation distinguishes configuring a workflow from building its infrastructure and proposes measuring shipped output against human effort and inference use.

ARIA: turn production traces into regression tasks for agent changes video thumbnail Play video
AI Engineer September 26, 2026 video

ARIA: turn production traces into regression tasks for agent changes

Zubin Aysola’s publisher notes describe an agent-improvement loop that converts production interactions into offline tasks and compares candidate configurations with the deployed agent. The system synchronizes research and production code, builds and tears down task environments, and scores both completion and relative behavior. A demonstration reproduces an SDK-usage failure and proposes an instruction change. It shows a regression workflow, without establishing a quantified improvement or unrestricted autonomous self-modification.

Black Hat Asia 2026 | Remote Server, Local Root. Welcome to MCP. video thumbnail Play video
Black Hat August 20, 2026 video

Black Hat Asia 2026 | Remote Server, Local Root. Welcome to MCP.

The researchers reverse the MCP authorization threat model: a malicious remote server can supply dynamic authorization metadata that vulnerable browser, process, or hybrid clients pass into privileged URL-opening and login flows. Reported outcomes across tested clients include local execution, account takeover, and cross-tenant data access, with multiple vendor confirmations.

Fine-Grained Authorization: The Missing Piece in Agentic AI Security - Shivay Lamba - NDC Sydney video thumbnail Play video
NDC Conferences YouTube July 29, 2026 video

Fine-Grained Authorization: The Missing Piece in Agentic AI Security - Shivay Lamba - NDC Sydney

Shivay Lamba explains how fine-grained, relationship-based authorization can enforce per-user and per-document access in RAG and agent pipelines. The talk uses OpenFGA and LangChain to demonstrate authorization inside retrieval flows, with patterns for multi-tenant isolation, vector-database integration, and auditable decisions rather than relying on retrieval filters or prompt instructions.

METR July 21, 2026 framework

Expenditure Horizon: Measuring Optimization Ability, with an Application to NanoGPT

METR proposes expenditure horizon: the budget where an agent's improvement on an optimization problem equals a human's improvement at the same cost. Six NanoGPT runs illustrate cost-performance curves, expensive experiment compute, revalidation that erased apparent gains from some models, maintainer judgments that only about 70% of stronger-model contributions were mergeable, and important contamination and hybrid-work limitations.

METR July 8, 2026 analysis

Because 8 ≈ e², Anthropic's researcher uplift is plausibly >2x

A METR research note models Anthropic's reported eightfold increase in merged code per contributor using CES production assumptions. It estimates that coding agents probably raised total researcher output by more than 2x, with a central estimate near 2.5x, while explicitly testing caveats such as code verbosity, low-value task expansion, and whether lines of code reflect research value.

Trail of Bits Blog July 2, 2026 analysis

GPT-5.5-Cyber built a zlib fuzzing lab in a day

Trail of Bits describes supervising GPT-5.5-Cyber as it built ASan and UBSan variants, derived seed corpora, and wrote fuzz harnesses for roughly a dozen zlib entry points in one day. The useful result is the workflow and its emphasis on reachability and reportability; vulnerability details remain under coordinated disclosure and the speed comparison is the authors' estimate.