•Security researchers demonstrated 15 unique zero-day vulnerabilities on day two of Pwn2Own Berlin 2026, earning over $385,000 in cash awards.
•Major exploits included remote code execution with SYSTEM privileges on Microsoft Exchange and privilege escalation on Windows 11 and Red Hat Enterprise Linux.
•Zero-days were also disclosed in AI coding agents like Cursor AI and OpenAI Codex, highlighting growing security concerns in emerging AI platforms.
•Google has reportedly claimed that criminals utilized an AI-generated zero-day exploit in a coordinated mass hacking attempt.
•This marks a significant, and potentially alarming, escalation in the use of artificial intelligence for offensive cyber operations.
•While specific details about the AI models, vulnerability, or targets remain scarce, the incident highlights the urgent need for enhanced AI-driven cybersecurity defenses.
•Anthropic's new LLM, Claude Mythos Preview, demonstrates 'strikingly capable' cybersecurity abilities, identifying and exploiting zero-day vulnerabilities across major OSes and web brow...
•The model can construct highly complex exploits, including multi-vulnerability chains, JIT heap sprays, and autonomously achieve local privilege escalation via race conditions and KASLR bypasses.
•Project Glasswing has been launched to leverage Mythos Preview for securing critical software and to prepare the industry for advanced AI-driven cyber challenges.
•Over 99% of the vulnerabilities found by Mythos Preview are unpatched, underscoring the urgency for improved defensive strategies across the industry.
•Security researchers demonstrated 15 unique zero-day vulnerabilities on day two of Pwn2Own Berlin 2026, earning over $385,000 in cash awards.
•Major exploits included remote code execution with SYSTEM privileges on Microsoft Exchange and privilege escalation on Windows 11 and Red Hat Enterprise Linux.
•Zero-days were also disclosed in AI coding agents like Cursor AI and OpenAI Codex, highlighting growing security concerns in emerging AI platforms.
•Google has reportedly claimed that criminals utilized an AI-generated zero-day exploit in a coordinated mass hacking attempt.
•This marks a significant, and potentially alarming, escalation in the use of artificial intelligence for offensive cyber operations.
•While specific details about the AI models, vulnerability, or targets remain scarce, the incident highlights the urgent need for enhanced AI-driven cybersecurity defenses.
•Anthropic's new LLM, Claude Mythos Preview, demonstrates 'strikingly capable' cybersecurity abilities, identifying and exploiting zero-day vulnerabilities across major OSes and web brow...
•The model can construct highly complex exploits, including multi-vulnerability chains, JIT heap sprays, and autonomously achieve local privilege escalation via race conditions and KASLR bypasses.
•Project Glasswing has been launched to leverage Mythos Preview for securing critical software and to prepare the industry for advanced AI-driven cyber challenges.
•Over 99% of the vulnerabilities found by Mythos Preview are unpatched, underscoring the urgency for improved defensive strategies across the industry.