Tag: vulnerability-disclosure
All the articles with the tag "vulnerability-disclosure".
-
Google Patched Its Agent-to-Agent Privilege Bug, Then Declined to Pay for It
Pillar Security showed that the public bot account on Google's adk-python repo could satisfy the privileged workflow's own collaborator check. Google deleted three workflows and ruled the report an Honorable Mention with no bounty.
-
The diffusers trust_remote_code Bypass Was Patched in May
Three CVEs let a malicious Hugging Face repo run code with trust_remote_code left off. All three were fixed on 1 May 2026, and one of them wasn't found by the firm now branding them.
-
54 Fake CVEs in Four Days, and Nobody Checked
JFrog found a GitHub repo that published 55 CVE advisories in four days, 54 of them fabricated. The CVE pipeline has no reproduction requirement, and generative AI just made that cheap to exploit.
-
Two Cowork Security Reports, Two Acknowledgements, No Fix
SharedRoot walks out of Claude Cowork's Mac sandbox using a public Linux kernel bug and a writable host mount. Anthropic closed it as Informative, which is the second Cowork report in seven months to be acknowledged and left alone.