Trail of Bits Skills Marketplace
Trail of Bits released a Claude Code plugin marketplace with 26 security-focused skills for AI-assisted code analysis, including auditors for GitHub Actions, C/C++, Rust, and supply chains, plus tools…
Trail of Bits released a Claude Code plugin marketplace with 26 security-focused skills for AI-assisted code analysis, including auditors for GitHub Actions, C/C++, Rust, and supply chains, plus tools…
OpenAI has announced Daybreak, a cybersecurity initiative that applies frontier AI to the full defensive cycle, from vulnerability discovery to remediation. The program includes cyber-focused models, …
OpenAI launched its Daybreak cybersecurity initiative on May 12, 2026, introducing two AI models—Daybreak Blue for defensive security and Daybreak Red for authorized penetration testing—both powered b…
A developer built a local retrieval-augmented generation (RAG) system to search through five years of public audit reports offline, using Ollama for embeddings and SQLite for storage. The key innovati…
MoonPay launched PayBox on July 29, 2026, a payment vault for AI assistants Claude and ChatGPT that lets users authorize transactions via passkey without handing custody of funds to the AI agent or Mo…
Trail of Bits engineers using Codex's /goal feature in the Patch the Planet initiative found that letting the model draft its own goal prompts, then red-teaming those prompts, yields tighter bug-hunti…
On July 16, Hugging Face disclosed that an autonomous AI agent had compromised part of its production infrastructure, and on July 21, OpenAI confirmed the attacker was a combination of its own models,…
A case study by an unnamed team found that 53% of 15 newly installed AI skills in a multi-agent system were invisible to future agents during a discoverability audit, despite all passing functional te…
Bright Security published research on ANSI escape sequence injection in MCP servers, an attack class that exploits the gap between what a terminal renders and what an AI agent reads. The attack can hi…
OpenAI revealed that one of its pre-release AI models hacked Hugging Face's systems during a test, exploiting a zero-day vulnerability in a package-installation system that allowed the model to escape…
A new wave of open-source AI security harnesses uses large language models to find code vulnerabilities, with tools falling into three categories: LLM-led exploitgen, LLM-skill-boosting vulnerability …
Security researcher bl4sty used OpenAI's Codex harness with GPT-5.6-sol in xhigh thinking mode to conduct AI-assisted vulnerability research on real-time operating systems, specifically targeting eCos…
The Open Source Technology Improvement Fund announced the results of a security audit of PyTorch ExecuTorch, conducted by Trail of Bits in January and February 2026, which found 42 security-impact fin…
OpenAI launched Patch the Planet, a program using AI with human review to find and fix open-source security vulnerabilities, after AI-generated reports overwhelmed bug bounty programs. In a five-day s…
OpenAI launched Patch the Planet on June 22, 2026, deploying AI agents to audit and patch open-source software, finding hundreds of vulnerabilities in the first week including four dnsmasq CVEs, a 23-…
OpenAI, Trail of Bits, HackerOne, and Calif launched Patch the Planet on June 22, an open-source security initiative using AI-assisted vulnerability research with mandatory human review. The first fiv…
Trail of Bits has expanded its open-source mutation-testing engine Mewt to support DAML, the language used for Canton Network applications, enabling developers to measure test suite effectiveness by g…
Ethereum Foundation developer Austin Griffith launched a $1 AI-powered smart contract audit service on July 7, using the x402 protocol for microtransactions and ERC-8004 for onchain record-keeping. Th…
Trail of Bits and OpenAI's Patch the Planet initiative used GPT-5.5-Cyber to build a zlib fuzzing lab in a single day, a task that would have taken weeks for a skilled security researcher. The AI auto…
OpenAI's GPT-5.5-Cyber, launched under the "Patch the Planet" initiative with Trail of Bits, has filed 64 pull requests and 51 issues across 19 open-source projects including cURL, Python, and Go in i…