<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability-Research on CuraSec</title><link>https://curasec.metacog.co.kr/tags/vulnerability-research/</link><description>Recent content in Vulnerability-Research on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 19:07:02 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/vulnerability-research/index.xml" rel="self" type="application/rss+xml"/><item><title>GraftyVul: Vulnerability Grafting System for Reproducible Exploit Datasets</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-graftyvul-synthesising-insecure-programs-through-real-world/</link><pubDate>Mon, 31 Aug 2026 19:07:02 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-graftyvul-synthesising-insecure-programs-through-real-world/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Useful for engineers evaluating or building SAST/vulnerability-detection tooling — GraftyVul&amp;rsquo;s reproducible, exploit-verified benchmark across five languages and 23 CWE categories offers a more realistic test corpus than most existing datasets.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Weird Machine Theory Extended to TLS Handshake (OpenSSL/BoringSSL)</title><link>https://curasec.metacog.co.kr/insights/2026-08-17-weird-machines-in-transport-layer-security/</link><pubDate>Mon, 17 Aug 2026 13:03:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-17-weird-machines-in-transport-layer-security/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The paper demonstrates that standard TLS primitives in OpenSSL and BoringSSL can be composed into an authentication bypass — a novel vulnerability class worth understanding for future TLS configuration and library choices. No CVE, no patch, and no KEV/EPSS signals mean no immediate action on running systems today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The research shows how TLS handshake state can be weaponized without triggering conventional signature-based detection, which has long-term implications for anomalous handshake detection; however, no IOCs, no active exploitation, and no ATT&amp;amp;CK mappings make this a future reference rather than a hunt trigger now.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>CyberForge: Synthetic Vuln Injection Framework for LLM Security Agent Training</title><link>https://curasec.metacog.co.kr/insights/2026-08-10-cyberforge-verified-vulnerability-injection-at-repository-le/</link><pubDate>Mon, 10 Aug 2026 13:39:41 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-10-cyberforge-verified-vulnerability-injection-at-repository-le/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research introduces a scalable method for generating validated C/C++ vulnerability training corpora that outperforms CVE-data augmentation; worth tracking as it may influence the next generation of AI-assisted SAST and patch-suggestion tools, but no change to running systems today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Unit 42 NOVA AI System Claims 14K+ OSS Zero-Days Discovered</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-the-frontier-ai-vulnerability-burst-industrializing-autonomo/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-the-frontier-ai-vulnerability-burst-industrializing-autonomo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> AI-driven autonomous vuln discovery at scale signals that OSS dependency risk will accelerate; no specific CVEs or patches to act on now, but worth tracking whether any findings surface in packages you run.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This research signals a coming wave of AI-generated vulnerability disclosures in OSS; worth factoring into board conversations about supply-chain risk and budget for SCA tooling investment.&lt;/li>
&lt;/ul></description></item><item><title>GitHub Halves Public Bug Bounty Payouts, Reserves Top Tier for VIP Researchers</title><link>https://curasec.metacog.co.kr/insights/2026-07-23-github-cuts-public-bug-bounty-payouts-moves-top-rewards-to-v/</link><pubDate>Thu, 23 Jul 2026 12:47:45 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-23-github-cuts-public-bug-bounty-payouts-moves-top-rewards-to-v/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> GitHub&amp;rsquo;s restructuring signals a broader shift toward tiered, invite-only vulnerability research programs; useful benchmarking context if your organization runs or is considering a bug bounty program, but no immediate action required.&lt;/li>
&lt;/ul></description></item><item><title>open-kritt: AI agent framework for automated vuln discovery</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-kritt-ai-open-kritt-133/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-kritt-ai-open-kritt-133/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> An open-source AI agent orchestration tool aimed at automated code vulnerability discovery — worth evaluating for AppSec pipelines, but no exploitation pressure or immediate action required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Opinion: Vulnerability research is broken as a field</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-vulnerability-research-is-cooked/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-vulnerability-research-is-cooked/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> A high-signal HN discussion (267 points) on the structural dysfunction in vuln research is worth reading to calibrate how much weight to give CVE feeds and vendor advisories.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Industry critique of vulnerability research incentives is relevant background for evaluating how your team prioritizes CVE-driven work and what that means for your risk posture.&lt;/li>
&lt;/ul></description></item><item><title>176 vulnerabilities documented in Samsung preinstalled Android apps</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-oversecured-samsung-vulnerabilities-183/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-oversecured-samsung-vulnerabilities-183/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> A dense research compilation covering Android preinstalled-app attack surface (IPC abuse, content provider exposure, etc.); worth reviewing if mobile or Android MDM is in scope, but no exploitation signals and no patch action available today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>AI Tool Mythos Discovers Vulnerability in curl</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-mythos-finds-a-curl-vulnerability/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-mythos-finds-a-curl-vulnerability/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> curl (and libcurl) is present in virtually every Linux system, container image, and language runtime, making any disclosed vulnerability worth tracking; review your deployed curl versions and schedule a patch once the fix is available, but no exploitation signals exist to force emergency action.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no exploitation, and no detection surface are present in this disclosure; the more notable angle is that an AI-assisted analysis tool surfaced a real bug in a ubiquitous open-source library, which is worth tracking as a signal of where automated vuln discovery is heading.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Claude Code discovers 23-year-old Linux vulnerability via AI analysis</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-claude-code-found-a-linux-vulnerability-hidden-for-23-years/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-claude-code-found-a-linux-vulnerability-hidden-for-23-years/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Demonstrates AI-assisted static analysis surfacing a long-latent Linux kernel bug; follow the linked write-up to identify the affected component and check whether your kernel version is patched, but no KEV listing or exploitation signals justify immediate action.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, TTPs, or active exploitation described; interesting for understanding AI-driven bug discovery workflows but yields no detection or hunt work today.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>LLMs generating kernel security reports that drive code removal</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-kernel-code-removals-driven-by-llm-created-security-reports/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-kernel-code-removals-driven-by-llm-created-security-reports/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> LLM-assisted vulnerability discovery is reaching the Linux kernel&amp;rsquo;s upstream review process; worth understanding how AI-generated security reports may reshape how CVEs get identified and patched in open-source dependencies you pull in.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> AI tooling is beginning to influence upstream open-source security maintenance at scale; useful context for future board discussions on AI-assisted security investment and supply-chain risk.&lt;/li>
&lt;/ul></description></item><item><title>SeedSmith: LLM-Agentic Seed Synthesis for Directed Fuzzing</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-seedsmith-llm-driven-seed-synthesis-for-directed-fuzzing/</link><pubDate>Mon, 13 Jul 2026 14:30:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-seedsmith-llm-driven-seed-synthesis-for-directed-fuzzing/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel research showing an LLM-agentic pipeline that improves directed fuzzer crash-trigger rates by generating semantically aware seed corpora; worth evaluating if your team runs fuzzing campaigns against internal C/C++ codebases, but no immediate change to running systems is required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Multi-Agent LLM System for Automated Vulnerability Discovery</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-multi-agent-llm-system-for-automated-vulnerability-discovery/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-multi-agent-llm-system-for-automated-vulnerability-discovery/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Academic research on using LLM agent pipelines to automate vuln discovery and reproduction; no enrichment signals or active exploitation. Worth reading to understand where AI-assisted offensive tooling is heading and how to stress-test your own AppSec review process.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, TTPs, or active campaigns tied to this research. Understanding AI-accelerated exploitation as an emerging attacker capability is background knowledge for future threat modeling, but yields no detection work today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This research signals that automated AI-driven vuln discovery is maturing, which is relevant for strategic conversations about AI threat landscape and investment in AppSec automation — but no immediate action or board-level event here.&lt;/li>
&lt;/ul></description></item></channel></rss>