CVE
A publicly catalogued software security flaw, each given a unique reference number.
A CVE, short for Common Vulnerabilities and Exposures, is a publicly listed software security flaw, each assigned a unique identifier so that everyone can refer to the same issue. The system is a cornerstone of how the security world tracks and fixes weaknesses.
CVEs have become an AI story because AI models are now being used to hunt for software bugs, and they are finding a lot of them. The number of serious vulnerabilities reported in a single month recently jumped several times over to a record high. That cuts both ways: the same skill that helps defenders find and fix flaws can help attackers discover them too.
For most people the practical lesson is unchanged but more urgent than ever: keep your software updated, because fixes for known CVEs only protect you once you install them.
-
This Open Model Got So Good at Finding Bugs That Its Own Maker Won't Release It Yet
-
Anthropic Put Its Most Restricted Model to Work Scanning Code for Bugs. A Human Still Has to Approve Every Fix
-
Researchers Encrypted the Attack So Grok Could Not Read It. Grok Decrypted It Itself
-
One Link Was Enough to Empty Your Copilot, and the Fix Took Eight Months
-
We Are Building an Invention Meant to Outgrow Its Inventors
-
A Chatbot Was Better at Running a Romance Scam Than Human Scammers Were
-
GLM-5.3 Got Much Better at Breaking Software, So Z.ai Is Holding the Weights Back
-
One Researcher, Under 20 Prompts, One Day: How AI Built a Zoom Attack
-
OpenAI Built a Model That Writes Exploits, and Handed It to a Short List of Companies
-
A real macOS flaw sat unreported because Apple's bug bounty inbox was buried in AI-written junk
-
AI is finding a flood of security flaws. Almost none of them get attacked
-
Anthropic checked 141,006 test runs and found three cases where Claude attacked real companies
-
A top-severity flaw in a popular AI agent tool let anyone run commands with a single request
-
OpenAI open-sources its vulnerability-hunting tool, and hands it to anyone with a terminal
-
1,200 AI lab employees ask Washington for a brake pedal they admit nobody knows how to build
-
Microsoft's new security model is small on purpose, and that is the interesting part
-
Defenders are now using prompt injection as a trap for AI attackers
-
GitLost: Researchers Tricked GitHub's AI Agent into Leaking Private Code
-
AI Is Now Hunting Software Bugs, and It's Finding a Lot of Them
-
Using Cursor? Update It Today, Two Serious Security Holes Just Got Fixed