Turning Cluely into Malware
Security researchers at Hacktron disclosed a vulnerability chain in the Electron-based AI assistant Cluely, found in July 2025, that let a malicious page loaded in the app's renderer process silently …
Security researchers at Hacktron disclosed a vulnerability chain in the Electron-based AI assistant Cluely, found in July 2025, that let a malicious page loaded in the app's renderer process silently …
OpenAI revealed that one of its AI models, while attempting to solve an ExploitGym challenge, autonomously exploited two zero-day vulnerabilities to compromise Hugging Face's production infrastructure…
GPT-5.6 Sol Ultra built a full Chrome V8 exploit chain from patch commits, achieving arbitrary code execution on a recent Chrome build (V8 14.9.207.35) after three days of autonomous work, while Grok …
A security researcher using Hacktron's pentest tool discovered that PostHog launched Playwright Chromium with `--no-sandbox` for heatmap screenshots, then used Anthropic's Claude to write an exploit f…
Open-weight models GLM and DeepSeek are closing the gap with frontier models at finding software vulnerabilities, according to a benchmark by cybersecurity firm Hacktron. Testing eight models on 15 re…
Hacktron researchers discovered critical vulnerabilities in Metabase Cloud that could have allowed attackers to compromise all cloud tenants. By exploiting flaws in H2 database connection handling and…