People are now tricking Meta’s AI support assistant to gain access to other people’s Instagram accounts.
This is exactly why AI should never have the authority to make account recovery decisions.
70% progress on a zero-click RCE 0-day in WebKit
Rekon AI — our pentesting framework — is closing in on a chain that targets the Safari engine running on every iPhone.
https://t.co/5zumVAnNAK
#0day#WebKit#Safari#AppleSecurity#infosec#cybersecurity#pentesting #AISecurity #redteam #appsec #vulnresearch #bugbounty #responsibledisclosure #browserexploitation
#JavaScriptCore #LATAM #ethicalhacking
Last month we launched Project Glasswing, our collaborative AI cybersecurity initiative. Since then, we and our partners have found more than ten thousand high- or critical-severity vulnerabilities in essential software.
Apple pasó 5 años construyendo una protección para blindar su sistema operativo.
Tres investigadores la esquivaron en 6 días usando Claude Mythos.
Apple diseñó MIE como la gran defensa de seguridad de los chips M5 y A19, una capa creada específicamente para bloquear la mayoría de hacks modernos incluso aunque existiera un bug dentro del sistema.
Según la propia compañía, impedía todos los exploits públicos conocidos en iOS moderno.
Pero el equipo de Calif encontró otra ruta.
No rompieron la protección directamente.
La rodearon.
Y lo más loco es la velocidad:
→ descubrieron el bug el 25 de abril
→ el 1 de mayo ya tenían un exploit funcional desarrollado con ayuda de Claude Mythos.
Un ataque extremadamente raro que no necesita modificar memoria crítica ni ejecutar malware de la forma tradicional.
Solo llamadas normales del sistema desde una cuenta sin privilegios, hasta conseguir acceso root en macOS.
Y fueron personalmente a Apple Park para entregar el informe técnico.
El paper completo tiene 55 páginas y se publicará cuando Apple lance el parche.
Posiblemente la historia del año en ciberseguridad.
Our security bug bounty program is now public on HackerOne.
We've run the program privately within the security research community, and their findings have strengthened our products. Now anyone can report vulnerabilities and get rewarded.
Read more: https://t.co/li1QvSTCMs
🚨 ¡BOMBA EN CIBERSEGURIDAD!
Una IA de Anthropic acaba de encontrar una vulnerabilidad de 27 AÑOS en OpenBSD y otra de 16 años en FFmpeg… que NADIE había visto antes (ni con millones de tests automáticos).
Y eso es solo el principio.
Se llama Project Glasswing: Anthropic + Apple + Google + Microsoft + AWS + NVIDIA + Cisco + CrowdStrike y más se unieron para usar IA defensiva y blindar el software crítico antes de que los atacantes la usen en contra nuestra.
Ya detectaron miles de zero-days en sistemas operativos, kernels de Linux y navegadores.
Anthropic está poniendo 100 MILLONES de dólares en créditos + donaciones para proteger código abierto.
El futuro de la ciberseguridad ya no es humano…
es IA vs IA.
Claude Code just got an "App Store" for agents 🤯
A massive new open-source library has dropped with 100+ pre-made agents, skills, and templates that you can install instantly.
And it's 100% free to use.
This is Gemini 3: our most intelligent model that helps you learn, build and plan anything.
It comes with state-of-the-art reasoning capabilities, world-leading multimodal understanding, and enables new agentic coding experiences. 🧵
We tested top foundation models on the International Olympiad in Informatics (IOI) - a programming competition that tests algorithmic thinking and C++ coding skills. We found @xai's @grok 4 to be the clear SOTA winner, scoring first place on both 2024 and 2025 exams. 🥇📊👏
@Trae_ai 6 months ago I became a pro user and they didn't give me a damn code for SOLO... but some useless guy who just created the account comes along and they give it to him lol