How we use /goal to find bugs in Patch the Planet
Codex's /goal feature achieved breakthrough results in the Patch the Planet initiative, discovering critical vulnerabilities in widely-audited open-source projects like Rust, curl, and zlib by combining AI-driven bug hunting with precise outcome definition rather than prescriptive instructions. The technique's success hinges on three key practices: letting Codex draft its own goal prompts based on threat models, defining desired outcomes with exacting specificity while avoiding step-by-step instructions, and assigning single focused objectives to each agent rather than competing goals. This approach enabled a single engineer to uncover vulnerabilities across major projects, including a soundness hole in Rust 1.98 and potential privilege-escalation bugs
Read full article at Trail of Bits ↗Related Articles
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.
The Vulnerability Gap: Why Discovery Is Outrunning Repair
AI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added CVE-2026-21962, an improper access control vulnerability affecting Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. The vulnerability poses significant risk as it allows total asset compromise post-exploitation, and CISA's Binding Operational Directive 26-04 requires federal agencies to prioritize rapid remediation of such high-risk KEV Catalog entries on publicly exposed systems. CISA encourages all organizations to adopt risk-based vulnerability management practices and prioritize remediation of cataloged exploited vulnerabilities.