Hacker Newsnew | past | comments | ask | show | jobs | submit | fromlogin
Weaponizing image scaling against production AI systems (trailofbits.com)
325 points by tatersolid 14 hours ago | past | 89 comments
Marshal madness: A brief history of Ruby deserialization exploits (trailofbits.com)
7 points by pentestercrab 1 day ago | past | discuss
Hijacking multi-agent systems in your PajaMAS (trailofbits.com)
7 points by Qwuke 2 days ago | past | 1 comment
MCP servers can attack you before you ever use them (trailofbits.com)
2 points by gtirloni 8 days ago | past | discuss
Trail of Bits' Buttercup wins 2nd place in AIxCC Challenge (trailofbits.com)
2 points by wslh 10 days ago | past | discuss
Buttercup is now open-source (trailofbits.com)
14 points by wslh 11 days ago | past | discuss
Buttercup is now open-source (trailofbits.com)
1 point by wrayjustin 12 days ago | past | discuss
Prompt injection engineering for attackers: Exploiting GitHub Copilot (trailofbits.com)
10 points by agentictime 12 days ago | past | 1 comment
Buttercup is now open-source (trailofbits.com)
15 points by wglb 13 days ago | past | discuss
GitHub Copilot Agent prompt injection via Issues (trailofbits.com)
2 points by feliperalmeida 13 days ago | past | discuss
Memory corruption in Nvidia Triton (as a new hire) (trailofbits.com)
2 points by ingve 16 days ago | past
Hijacking multi-agent systems in your PajaMAS (trailofbits.com)
2 points by frabert 21 days ago | past | 1 comment
We built the security layer MCP always needed (trailofbits.com)
3 points by wslh 24 days ago | past
Exploiting zero days in abandoned hardware (trailofbits.com)
113 points by ingve 27 days ago | past | 35 comments
Detecting code copying at scale with Vendetect (trailofbits.com)
2 points by gpi 30 days ago | past
Detecting code copying at scale with Vendetect (trailofbits.com)
2 points by ingve 31 days ago | past
Investigate Your Dependencies with Deptective (trailofbits.com)
2 points by ingve 44 days ago | past
Buckle up, Buttercup, AIxCC's scored round is underway (trailofbits.com)
1 point by wslh 50 days ago | past
Unexpected security footguns in Go's parsers (trailofbits.com)
234 points by ingve 64 days ago | past | 132 comments
Insecure credential storage plagues MCP (trailofbits.com)
4 points by mooreds 71 days ago | past
The Custodial Stablecoin Rekt Test (trailofbits.com)
2 points by wslh 81 days ago | past
The cryptography behind passkeys (trailofbits.com)
276 points by tatersolid 3 months ago | past | 263 comments
Making PyPI's test suite faster (trailofbits.com)
125 points by rbanffy 3 months ago | past | 39 comments
Making PyPI's test suite 81% faster (trailofbits.com)
8 points by zdw 3 months ago | past
Insecure credential storage plagues MCP (trailofbits.com)
2 points by wslh 3 months ago | past
Making PyPI's test suite 81% faster (trailofbits.com)
11 points by woodruffw 3 months ago | past | 2 comments
Deceiving users with ANSI terminal codes in MCP (trailofbits.com)
3 points by HypnoticOcelot 3 months ago | past | 1 comment
MCP servers can steal your conversation history (trailofbits.com)
1 point by ingve 3 months ago | past
Jumping the line: How MCP servers can attack you before you ever use them (trailofbits.com)
1 point by ingve 4 months ago | past
The future of Clang-based tooling (2023) (trailofbits.com)
2 points by fanf2 4 months ago | past

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: