BTC $83,857.49 +0.86%
ETH $2,697.54 +1.76%
BNB $763.03 -0.09%
XRP $1.50 +1.48%
SOL $118.93 +0.10%
TRX $0.3347 +0.34%
DOGE $0.0943 +1.22%
ADA $0.2473 +0.74%
BCH $310.39 +0.73%
LINK $14.99 +8.54%
HYPE $87.77 -1.49%
AAVE $156.29 +4.78%
SUI $1.12 -5.49%
XLM $0.2263 +8.26%
ZEC $1,399.36 -9.67%
AAPL $337.70 -0.85%
AMZN $246.37 -1.02%
GOOGL $342.59 +0.26%
MSFT $507.29 -1.76%
META $716.07 -2.22%
NVDA $229.66 +2.81%
TSLA $357.82 -3.20%
SNDK $1,720.52 -0.26%
INTC $115.63 -2.85%
SPCX $146.47 -1.73%
MU $1,066.18 +0.63%
AMD $609.07 -0.82%
BTC $83,857.49 +0.86%
ETH $2,697.54 +1.76%
BNB $763.03 -0.09%
XRP $1.50 +1.48%
SOL $118.93 +0.10%
TRX $0.3347 +0.34%
DOGE $0.0943 +1.22%
ADA $0.2473 +0.74%
BCH $310.39 +0.73%
LINK $14.99 +8.54%
HYPE $87.77 -1.49%
AAVE $156.29 +4.78%
SUI $1.12 -5.49%
XLM $0.2263 +8.26%
ZEC $1,399.36 -9.67%
AAPL $337.70 -0.85%
AMZN $246.37 -1.02%
GOOGL $342.59 +0.26%
MSFT $507.29 -1.76%
META $716.07 -2.22%
NVDA $229.66 +2.81%
TSLA $357.82 -3.20%
SNDK $1,720.52 -0.26%
INTC $115.63 -2.85%
SPCX $146.47 -1.73%
MU $1,066.18 +0.63%
AMD $609.07 -0.82%

vulnerabilities

All
Article
Flash

first_img Google disclosed the AI security agent PageBreak, which has identified over 500 vulnerabilities

The Google Product Security Team has disclosed an internal AI agent called PageBreak, used to test the security of its first-party web applications. This agent is built on Google's Gemini model and began a pilot program in November 2025, transitioning to a formal project in January 2026, with the goal of autonomously scaling vulnerability discovery and reducing manual input.Unlike common AI scanning tools, PageBreak hands over hypotheses to specialized validators after discovering suspicious defects, attempting actual exploitation in a real-time running copy of the application, and only reports once confirmed exploitable, with a false positive rate close to zero. Google claims that PageBreak has identified over 500 XSS vulnerabilities in its first-party web applications, which can be used to hijack login sessions, steal data, or impersonate users.Google stated that the security team has been overwhelmed in recent years by a large number of AI-generated vulnerability reports that appear reasonable but are not valid, making it a major challenge to distinguish real defects from hallucinations. When testing applications built using the next-generation high-assurance framework, PageBreak found only two vulnerabilities. The next step for Google is to integrate PageBreak with the automated remediation agent CodeMender, providing confirmed vulnerabilities with accompanying fixes.

Binance Security Announcement: Please iPhone users check if FomoPeek is installed, as it can exploit iOS vulnerabilities to gain maximum access to the device

Binance Wallet Security Announcement: iPhone users please check if you have installed the FomoPeek application. Binance has noted a recent security incident disclosed by the community. According to security companies such as SlowMist, the third-party application FomoPeek (versions 1.1-1.2) contains malicious code that can exploit vulnerabilities in the iOS system to gain maximum permissions on the device and may access sensitive data stored on the device, including private keys, mnemonic phrases, login credentials, chat records, files, etc. Please note that such malware directly attacks the device itself. If the attack is successful, all application data on the affected device may be accessed.Please check the following:Are you using an iPhone or iPad running iOS 26.x or earlier?Have you installed the FomoPeek application?If both of the above apply to you, it is recommended to take the following steps immediately:Delete the FomoPeek application and do not reinstall it.Update the iOS system to the latest version.For users with self-hosted wallets: Create a new wallet on a device that has never installed the application and transfer assets to the new wallet address.If you notice any unusual asset activity, please retain the affected device and relevant evidence, and contact customer service for further investigation.At the same time, all users are reminded: Do not install applications from untrusted sources and keep your device software up to date.

first_img The EU Cyber Resilience Act comes into effect, requiring cryptocurrency wallet providers to report vulnerabilities within 24 hours

According to Cointelegraph, the European Union's Cyber Resilience Act (CRA) officially came into effect on September 11, requiring cryptocurrency hardware and software wallet providers to submit early warning reports within 24 hours upon discovering actively exploited vulnerabilities or serious security flaws, and to submit complete notifications within 72 hours. Manufacturers must also submit final reports within 14 days after taking corrective or mitigating measures, while serious incidents must be reported within one month.The European Commission stated that the new reporting requirements aim to better protect consumers and businesses from cyber threats, applicable to all "products with digital elements" sold in the EU market, and are built upon the EU's broader cybersecurity strategy. According to the penalty provisions of the final draft, companies that fail to comply with Articles 13 and 14 may face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing incorrect, incomplete, or misleading information may also incur fines of up to €5 million.Before the implementation of this measure, several hardware wallet manufacturers recently disclosed incidents of user data breaches. On September 4, Trezor revealed that a data breach involving its logistics provider ShipMonk affected approximately 67,000 U.S. customers, exceeding the initial estimate of 14,000; this week, Trezor and BitBox also warned users to be cautious of phishing emails disguised as urgent security notifications. In June, the Layer-1 blockchain network Zilliqa warned of vulnerabilities in its Ledger application, where attackers could exploit publicly available on-chain data to recover user private keys.

first_img OpenAI's new model Astra can autonomously discover and exploit software vulnerabilities, rated as "critical" in cybersecurity capability level

OpenAI stated that its upcoming Astra model can autonomously discover previously unknown software vulnerabilities and convert them into usable attack vectors without human intervention, making it the company's first model to reach the "Critical" cybersecurity capability level threshold. In a blog post released on Tuesday, OpenAI mentioned that according to its Preparedness Framework, reaching this level means the model can discover zero-day vulnerabilities and develop usable exploit code in hardened real systems without human involvement, or design and execute attacks based solely on a high-level objective.In testing, Astra achieved a 100% score in benchmark tests for developing exploit code based on known vulnerabilities and discovered two previously unknown vulnerabilities in another internal test. Additionally, the model successfully broke through a hardened browser sandbox and executed commands on the host machine, while gaining root access by exploiting multiple weaknesses in the operating system. OpenAI stated that it has delayed some of Astra's development progress to enhance security measures and plans to make its advanced cybersecurity capabilities available only to selected testers.This capability is particularly relevant to the cryptocurrency industry, as software vulnerabilities can be converted into financial losses within minutes. CoinDesk reported in June that increasingly powerful AI models can compress the process of searching code, discovering misconfigurations, and assembling attacks from days or weeks to machine speed. Security researchers noted at the time that the significant change was not the emergence of new categories of attacks, but rather the dramatically increased speed at which existing vulnerabilities are discovered and exploited.

first_img Polygon has fixed security vulnerabilities through two hard forks, which were previously deployed privately

Polygon Labs disclosed that it has fixed a batch of security vulnerabilities in its proof-of-stake network through two hard forks, with the related fixes privately deployed before public disclosure. According to a forum post released on Wednesday, the team packaged the fixes into the Austin hard fork of the Bor client and the Kyoto hard fork of the Heimdall client, both of which followed the standard process for fixing issues that affect consensus: first validated on the Amoy testnet, and then publicly disclosed once the mainnet was activated and the network was secure.The Austin fork fixed two denial-of-service paths in block processing, including a vulnerability where malicious block producers could crash peer nodes by filling them with oversized field data. The Kyoto fork addressed a broader range of consensus hardening issues, with the most severe vulnerability allowing an attacker to force the entire validator set to perform costly and coordinated work with just one crafted transaction—the cost of constructing the transaction is low, but the network processing cost is high. Polygon emphasized that none of the vulnerabilities were observed to be exploited on the mainnet and have been proactively addressed. The two upgrades are now mandatory for node operators and have taken effect without the need for state migration or resynchronization.This disclosure comes at a critical transformation period for Polygon, which has completed the migration of the traditional MATIC token to POL as part of a comprehensive overhaul of its network architecture. The news did not boost the price of POL; according to CoinGecko data, POL traded at approximately $0.09983 on Sunday, down 2.3% in 24 hours, down about 6.8% over the past week, and down about 60.8% over the past year, with a market capitalization of approximately $1.07 billion.

Core Lightning, the Bitcoin Lightning Network software, issued an emergency warning due to the discovery of multiple real vulnerabilities in an AI report

According to CoinDesk, the developers of the Bitcoin Lightning Network payment software Core Lightning (CLN) issued an urgent warning to node operators after the team received a large number of AI-generated security reports, revealing several real vulnerabilities. The development team advised operators not to directly shut down the machine power but to restart the software in "--offline" mode, which stops communication with other Lightning Network nodes while still keeping it operational to continuously monitor the Bitcoin blockchain and protect the funds in the payment channels.The Core Lightning team began receiving a large number of AI-generated vulnerability reports since early August, some of which have been confirmed to be valid. Developers will keep the details confidential for two weeks to complete the patch development and plan to release a signed patch version for operators to verify the source. The source code and vulnerability details will be made public after the confidentiality period ends.This is the second AI-related security incident in the Lightning Network this month. Earlier in early August, BTCPay Server experienced a vulnerability that led to the leakage of credentials for some Lightning Network nodes and theft of funds. Additionally, the "Bitcoin Red Team," composed of 16 developers, used AI models to scan 390 Bitcoin code repositories at the end of July, discovering nearly 5,000 issues, 85 of which were rated as critical.
app_icon
ChainCatcher Building the Web3 world with innovations.