← Back
VulnerabilityTrail of Bits·1 month ago

GPT-5.5-Cyber built a zlib fuzzing lab in a day

GPT-5.5-Cyber autonomously built a sophisticated fuzzing lab for zlib in a single day—work that would typically take security researchers weeks—discovering multiple vulnerabilities through dynamic testing rather than static analysis. Trail of Bits' "Patch the Planet" initiative is racing to find and patch bugs in open-source projects before advanced AI models democratize vulnerability discovery for attackers. The critical takeaway: the technical barrier protecting unmaintained codebases has collapsed, making proactive AI-driven security audits an urgent necessity for all security-critical software.

Read full article at Trail of Bits

Related Articles

VulnerabilityThe Hacker News·8 hours ago

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.

VulnerabilityCISA Advisories·11 hours ago

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-21962, an improper access control vulnerability affecting Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. The vulnerability poses significant risk as it allows total asset compromise post-exploitation, and CISA's Binding Operational Directive 26-04 requires federal agencies to prioritize rapid remediation of such high-risk KEV Catalog entries on publicly exposed systems. CISA encourages all organizations to adopt risk-based vulnerability management practices and prioritize remediation of cataloged exploited vulnerabilities.