Toggle light / dark theme

AIAssisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache ZeroDay

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors.

PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning was authorized through bug bounty or vulnerability disclosure programs and found roughly 700 vulnerable targets before deeper validation and RQP research.

Kettle said those findings involved banks, government infrastructure, security products, and an airport.

AI and ‘Ramanomics’ could eliminate a major obstacle to studying living cells

Fluorescent dyes have long been used in biological research to identify and visualize structures within living cells. Although effective, they have several drawbacks, including altering the cells under study, limiting the number of structures that can be examined at once and reducing measurement accuracy.

A team led by University at Buffalo researchers has developed a new method that draws on advances in artificial intelligence and Raman spectroscopy to overcome the limitations of dye-based imaging.

The approach combines AI with “Ramanomics,” a UB-pioneered optical technology that measures the biochemical makeup of cells without altering them. Rather than relying on fluorescent labels, which are dyes that bind to specific cellular components and glow under specialized lighting, it identifies cellular structures by their unique biochemical signatures.

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.

Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed controllers, not water utilities or confirmed victims.

Forescout said the publicly described effects could be achieved without a vulnerability exploit: attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment.

Meta AI model hacked a company during misconfigured cyber test

Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI’sOpenAI’s initial disclosure that its agents breached Hugging Face.

The Information was the first to report the incident on Wednesday, citing people familiar with the matter who said Meta’s Muse Spark 1.1 model breached an unidentified company and made changes to its internal systems.

According to the report, the model reached the public internet because of an error in the configuration of a sandbox testing environment operated with independent cybersecurity evaluation company Irregular.

Connecting Data, Computing, and AI for Scientific Discovery

As Director of the Scientific Data Division at Lawrence Berkeley National Laboratory, Ana Kupresanin leads scientists and engineers who develop the methods, software, workflows, and infrastructure needed to make scientific data usable, reliable, and reusable for science and AI. The division works across the scientific data lifecycle, helping researchers organize, curate, manage, access, analyze, and reuse data, while also developing machine learning methods, high-performance computing workflows, and partnerships with domain scientists across disciplines.

Kupresanin is a statistician and a Fellow of the American Statistical Association. Before joining Berkeley Lab in 2023, she spent more than a decade at Lawrence Livermore National Laboratory, where she held scientific and leadership roles and worked with researchers across fields to develop statistical methods, analyze complex data, and address uncertainty quantification problems.

That background shapes how she thinks about AI for science. Scientific data are not generic inputs to a model. They come from experiments, simulations, instruments, and observations, each with its own assumptions, limitations, uncertainties, and context. Kupresanin’s work focuses on bringing statistical thinking, machine learning, and data infrastructure together so that AI systems can be more reliable, interpretable, and useful for scientific discovery.

Claude Fable 5 AI finds a tiny formula that topples an 87-year-old math conjecture

A mathematician working at Anthropic says he used the AI model Claude Fable 5 to uncover a remarkably simple counterexample to the Jacobian conjecture, a famous problem that has resisted mathematicians for more than a century. The result shows that the conjecture is false in three dimensions and above, although the original two-dimensional version remains unsolved.

/* */