Tagged articles

vulnerability discovery

6 articles · Page 1 of 1
Machine Learning Algorithms & Natural Language Processing
Machine Learning Algorithms & Natural Language Processing
Sep 3, 2026 · Artificial Intelligence

OpenAI's Astra (GPT-6) Revealed: Cyber-Critical Capabilities, Safety Struggles, and Chinese Researchers Behind It

OpenAI's next-gen model Astra achieves cyber-critical capabilities with 100% success on ExploitBench and 4x vulnerability-finding over GPT-5.6 Sol, but delayed release due to safety concerns; Altman describes excitement and anxiety, while Chinese researchers Jiawei Liu and Xiangyu Qi lead key security work.

AI safetyAstraGPT-6
0 likes · 13 min read
OpenAI's Astra (GPT-6) Revealed: Cyber-Critical Capabilities, Safety Struggles, and Chinese Researchers Behind It
Black & White Path
Black & White Path
Jun 12, 2026 · Information Security

How Skills and MCP Influence AI‑Driven Vulnerability Discovery

The article reviews two recent posts on AI‑assisted security testing, explains how Skills can limit large‑model performance, argues that MCP provides richer tooling, and shares a practical Burp MCP workflow with code snippets for traffic analysis in vulnerability research.

AI AgentBurp SuiteMCP
0 likes · 6 min read
How Skills and MCP Influence AI‑Driven Vulnerability Discovery
AI Explorer
AI Explorer
Mar 4, 2026 · Information Security

Shannon AI Hacker Achieves 96% Success in Automated Web Vulnerability Detection

Shannon, an autonomous AI-driven penetration testing agent, bridges the speed‑security gap created by rapid AI‑assisted coding by automatically analyzing source code, mapping attack paths, and executing real exploits, achieving a 96.15% success rate on the XBOW benchmark and uncovering over 20 critical flaws in the OWASP Juice Shop demo.

AIPenetration Testingautomation
0 likes · 7 min read
Shannon AI Hacker Achieves 96% Success in Automated Web Vulnerability Detection
Laravel Tech Community
Laravel Tech Community
Mar 12, 2021 · Information Security

Exploiting a High‑Risk SSRF Vulnerability in a Financial Crowdsourcing Web Application

The article details a step‑by‑step penetration test of a seemingly empty financial web application, describing how hidden JavaScript files and a discovered /xxxapi/file/pdf/view endpoint were leveraged to craft an SSRF payload that accessed internal services such as Elasticsearch, illustrating practical web security exploitation techniques.

JavaScript analysisPenetration Testingssrf
0 likes · 7 min read
Exploiting a High‑Risk SSRF Vulnerability in a Financial Crowdsourcing Web Application