Your Permission List Can't See Taint
Anthropic's Claude Code permission system is vulnerable to prompt injection because its flat allowlist cannot track the provenance of tool calls, a concept known as 'taint' that has existed since Perl…
Anthropic's Claude Code permission system is vulnerable to prompt injection because its flat allowlist cannot track the provenance of tool calls, a concept known as 'taint' that has existed since Perl…
Linus Torvalds defended the use of AI tools in Linux kernel development, responding to a debate about integrating the agentic LLM code review tool Sashiko into the kernel's Patchwork tracking system. …
Nebula Security's AI platform VEGA uncovered GhostLock, a use-after-free vulnerability in the Linux kernel's futex implementation that has existed since version 2.6.39 (2011). The bug allows any unpri…
Linux creator Linus Torvalds firmly rejected anti-AI sentiment on the Linux kernel mailing list, stating that the kernel project is not anti-AI and that AI is a useful tool. Torvalds said he will "abs…
Farid Zakaria developed a tool called anubis-fetch that easily bypasses Anubis, a proof-of-work proxy designed to block AI scrapers from accessing Linux kernel mailing list threads. The author argues …
The Zig project has banned all LLM-generated contributions, calling them "invariably garbage," and Godot and the Linux kernel have followed with similar policies requiring disclosure of AI tool usage.…
Linux kernel developers are debating whether to simplify or eliminate the requirement for AI/LLM agent attribution in patches, with prominent developer Christian Brauner arguing the current policy cre…
Linux kernel maintainer Greg Kroah-Hartman says AI-generated security reports and patches have dramatically improved over the past month, shifting from low-quality 'AI slop' to real, useful bug report…
Suren Baghdasaryan has proposed a guaranteed contiguous memory allocator patch set for the Linux kernel, building on the cleancache concept to reserve physically contiguous memory at boot for reliable…
Oracle-backed OpenJDK banned generative AI contributions in April 2026, citing reviewer burden, safety, and IP concerns, while Oracle's GraalVM project permitted them with optional disclosure. The con…
AI has made code generation cheaper but not ownership, shifting engineering work from creation toward supervision as the sign-off layer becomes the critical system. The Linux kernel's AI policy exempl…
Google's internal AI-based security scanning has discovered 17 bugs in Perfetto's trace processor over 10 weeks, a project that previously received little security attention. The bugs are high-quality…
Together AI disabled the vulnerable `algif_aead` kernel module across its entire infrastructure within hours of exploit details for CVE-2026-31431, a Linux kernel bug that gives unprivileged local use…
A self-orchestrating team of LLM-driven vulnerability-hunting agents has discovered over 20 CVEs in recent months, including CVE-2026-31432 and CVE-2026-31433, two remote, unauthenticated out-of-bound…