Feed aggregator

Show HN: AI Security Leaderboard – comparing cyber and CBRN safeguards

Hacker News - Wed, 07/29/2026 - 5:33pm

There's no shortage of leaderboards for model capabilities - but the security of models is becoming increasingly relevant, from the risk of an AI agent processing unsanitized input being hijacked to models being pulled due to cybersecurity jailbreaks. We developed an automated test suite that runs models through 1500 automatically generated jailbreak attempts and measures the number of universal jailbreaks: prompts that elicit compliant, detailed responses to >75% clearly harmful questions within a domain (like offensive cybersecurity). We find a big gap between the most robust models -- Fable 5 and GPT-5.6 Sol -- and other leading frontier models -- Gemini 3.1 Pro and Grok 4.5. This is v1.0 and we plan to update with new attacks and broader datasets in the future; we'd love to hear from HN what would be useful in your work!

Comments URL: https://news.ycombinator.com/item?id=49103367

Points: 3

# Comments: 0

Categories: Hacker News

Show HN: Play ROMs inline in your terminal

Hacker News - Wed, 07/29/2026 - 5:27pm

Article URL: https://github.com/jhickner/rom

Comments URL: https://news.ycombinator.com/item?id=49103304

Points: 1

# Comments: 0

Categories: Hacker News

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Cisco Security Advisories - Wed, 07/29/2026 - 4:00pm

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. 

Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.  

Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. 

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20316
Categories: Cisco

Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

Cisco Security Advisories - Wed, 07/29/2026 - 4:00pm

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products:

  • Catalyst SD-WAN
  • Integrated Management Controller (IMC)
  • IOS Software
  • IOS XE Software
  • RoomOS
  • Terminal Services Agent

To fully remediate vulnerabilities to be disclosed on August 5, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories.

For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer Focused Response to AI-Accelerated Vulnerability Discovery.

<br/>Security Impact Rating: Informational
Categories: Cisco

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

Cisco Security Advisories - Wed, 07/29/2026 - 3:55pm

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. 

This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2

This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20079
Categories: Cisco

Claude Is Down

Hacker News - Wed, 07/29/2026 - 3:50pm
Categories: Hacker News

Pages