I Tried build AI web vulnerable scanner
用AI把XSS检测从“反射”推进到“真实执行”,开源漏洞扫描器让误报无处遁形。
Article URL: https://github.com/tX-c0re/xss-grenade Comments URL: https://news.ycombinator.com/item?id=49386036 Points: 1 # Comments: 1
用AI把XSS检测从“反射”推进到“真实执行”,开源漏洞扫描器让误报无处遁形。
Article URL: https://github.com/tX-c0re/xss-grenade Comments URL: https://news.ycombinator.com/item?id=49386036 Points: 1 # Comments: 1
无需AI和注册,快速发现GitHub仓库中的ISO 27001/SoC 2合规性漏洞,4个真实检测器
Article URL: https://normos.io/free-github-scan Comments URL: https://news.ycombinator.com/item?id=49112124 Points: 1 # Comments: 0
微软正开发类似Anthropic Mythos的AI漏洞检测工具,采用模型路由技术,最快7月发布,安全领域新动向。
IT之家 7 月 17 日消息,据 The Information 报道,微软正在开发一款基于 AI 的漏洞检测工具,类似于 Anthropic 的 Mythos 模型。 知情人士透露,这款产品名为“感知项目”(Project Perception),这是一款全新的安全产品,旨在借助 AI 帮助企业…
用智能体方法对COTS二进制进行自动化漏洞推理,突破传统静态分析的局限,安全研究新范式。
arXiv:2605.05000v2 Announce Type: replace-cross Abstract: LLM agents have been increasingly adopted for solving security tasks. However, existing eval…
基于 Claude 的自主 AI 安全工具,实时检测漏洞并提供智能防护,让代码安全更高效。
Article URL: https://github.com/capitalone/VulnHunter Comments URL: https://news.ycombinator.com/item?id=48942583 Points: 1 # Comments: 0
OpenAI自曝内部“红队”模型GPT-Red,将提示注入攻击成功率从95%压至0.05%,AI安全实战效果惊人。
IT之家 7 月 16 日消息,OpenAI 当地时间 15 日介绍了其内部使用的网络安全“红队”模型 GPT-Red。 该模型可自动化地进行各种网络攻击模拟 ,帮助 OpenAI 提升对外模型产品的鲁棒性。 OpenAI 表示,其过去半年 自 GPT-5.3 后的每个生产模型均将“红队”模型用于训…
诺奖经济学家Acemoglu从AI怀疑者转为行动派,Meta因AI裁员遭诉,内存危机致手机销量暴跌——一周AI大事件速览。
이 글은 제 블로그에 처음 발행되었습니다 · Originally published at dbhyeong.github.io 2026년 7월 15일 기준 최근 이슈를 다이제스트로 묶었다. AI 대체론을 가장 앞장서 반박하던 노벨 경제학자 아제모을루가 '지금 행동하자'는 8…
别再手动验证候选bug了!AnyPoC自动生成可执行测试用例,让LLM漏洞检测从"疑似"走向"实锤",大幅提升自动化检测的可落地性。
arXiv:2604.11950v2 Announce Type: replace-cross Abstract: While recent LLM-based agents can identify many candidate bugs in source code, their reports…
HookProbe如何精准捕获Windchill高危漏洞?拆解CVE-2026-12569的检测思路与缓解方案。
Understanding and Mitigating CVE-2026-12569 in PTC Windchill and FlexPLM In the high-stakes world of Product Lifecycle Management (PLM), the integrity…
用分离逻辑核心为LLM漏洞检测提供可靠基础,兼顾召回率与精度,值得安全研究者细读
Article URL: https://lambdasec.github.io/Frame-Grounding-LLM-Vulnerability-Detection-with-a-Sound-Separation-Logic-Core/ Comments URL: https://news.yc…
从基准测试到现实场景,全面评估GNN与LLM在漏洞检测中的真实表现,揭示模型落地效果与挑战。
arXiv:2512.10485v2 Announce Type: replace-cross Abstract: Vulnerability detection methods based on deep learning (DL) have shown strong performance on…
不用标注数据也能精准识别漏洞?ANVIL利用LLM的异常检测新范式,突破监督学习局限
arXiv:2408.16028v4 Announce Type: replace-cross Abstract: Supervised-learning-based vulnerability detectors often fall short due to limited labelled t…
AI智能体能否实时拦截链上攻击?新基准CyberChainBench用真实漏洞拷问大模型安全能力,Web3开发者必读。
arXiv:2606.26216v1 Announce Type: cross Abstract: We present CyberChainBench, a benchmark for evaluating LLM-based agents on smart contract security a…
Anthropic最新AI模型在测试中成功发现政府机密系统漏洞,展现AI安全检测潜力。
IT之家 6 月 24 日消息,一名美国政府官员于当地时间周二向美联社透露,在一场测试演练中,人工智能公司 Anthropic 旗下一款 AI 模型,成功检出美国高度机密、高安全等级政府计算机系统存在多处漏洞。 这名要求匿名、以便谈论此事的官员表示,Anthropic 与美国多家情报机构合作,使用该…
系统评估LLM在真实Web漏洞检测中的表现,揭示能力与局限,安全从业者必读
arXiv:2606.21397v1 Announce Type: cross Abstract: Large Language Models (LLMs) have emerged as a promising tool for automated vulnerability detection,…
提交代码前自动扫描漏洞,守护 Git 仓库安全,开源轻量易上手。
Hello HN! I built a pre-commit code scanner that checks your staged changes for security vulnerabilities every time you run 'git commit'. I am an inex…
开源CLI工具,专查Supabase行级安全漏洞,防部署后数据泄露,精准覆盖CVE-2025-48757类风险。
Article URL: https://github.com/GerardoRdz96/rlsgate Comments URL: https://news.ycombinator.com/item?id=48614399 Points: 4 # Comments: 0
微调大模型检测系统漏洞,看似精准实则可能只是校准错觉,揭示能力边界的关键研究。
arXiv:2606.20502v1 Announce Type: cross Abstract: Whether LLMs scoring well on vulnerability benchmarks genuinely reason about security or merely patt…
LLM能否稳定复现漏洞发现?Snyk新基准测试揭示AI安全检测的可靠性
arXiv:2606.15762v1 Announce Type: cross Abstract: We ran 300 repeated vulnerability-finding scans to measure how repeatable agentic large language mod…
论文提出PI-Hunter,自动发现并精准定位大模型提示注入漏洞,为AI安全红队测试提供新方案。
arXiv:2606.12737v1 Announce Type: cross Abstract: Large Language Models (LLMs) are rapidly evolving into agentic systems that interact with external t…