Blog
AISLE Discovered Six curl CVEs After OpenAI and Anthropic Found Zero
After frontier AI systems came up empty, AISLE surfaced six CVEs in curl, one of the world's most audited codebases. Its maintainers patched all six.

AISLE Discovers 6 High and Critical CVEs in FFmpeg
AISLE's AI-native engine found six high and critical CVEs in FFmpeg, including a 9.8 remote heap overflow and a stack overflow that survived 19 years.

Attackers Are Using AI to Find Vulnerabilities in Your Code. Your SAST Was Never Even Looking for Them
Can AI-native code analysis replace SAST, or is it just a complement. Here's what data from real-world results shows.
AISLE Finds 21 Security Issues in FFmpeg, Including 6 New CVEs
AISLE uncovered 21 issues in FFmpeg, including 6 new CVEs spanning code execution and out-of-bounds reads. All patched, with commit links inside.

AISLE Discovers a One-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity
Learn how our AI found a one-click RCE vulnerability in 3 code editors: Cursor, VS Code, and Google Antigravity.

The Model That Fixes Your Code Might Hack the Linux Kernel
Learn how easy it is to trojanize a model, and what defenders can do to protect their supply chains from this emerging threat.

The Economics of Security Vulnerabilities: Why Discovery Is Not Commoditizing
If discovery is cheap, why are people willing to pay more for exploits than ever before? Here's what the market for exploits shows.

AISLE Finds 8 CVEs Across MySQL, MariaDB, and PostgreSQL
Learn how AISLE found 8 CVEs in critical databases using autonomous, AI-native analysis and verification.
.webp&w=3840&q=75)
AISLE Discovers 6 New CVEs in curl, Including the Oldest Issue Ever Reported
AISLE's analyzer discovered 6 new CVEs in curl, more than 2x the nearest AI security platform and including the oldest security issue in the project.

AISLE Won a Hacker News Cybersecurity Stars Award. Here's What It Means.
AISLE was named Most Innovative AI-Powered Vulnerability Management Platform by The Hacker News at the inaugural Star Awards. Here's why.
"Mythos" at Home, and It's Called AISLE
A startup out of Europe built an AI system that matches Mythos on zero-day discovery, using widely available models, even air-gapped.

Control Is the New Frontier in Security AI
Frontier AI can vanish overnight. For security teams, control is a requirement, not a luxury. Why sovereign AI is the new frontier in cyber defense.

Your Security Shouldn't Depend on Someone Else's API
Why the historical tension between frontier capability and full sovereignty is dissolving, and why deployment-agnostic AI security is the answer.
.webp&w=3840&q=75)
Announcing AISLE Snapshot: Rapid AI Code Analysis for Every Environment
Introducing AISLE Snapshot, the rapid AI code audit that delivers frontier-class security findings to air-gapped, on-prem, and cloud environments.

AISLE Finds 4 CVEs in One of the World’s Most Popular IoT Platforms
Learn how AISLE's analyzer agents found four CVEs in one of the world's most popular embedded platforms.
%25203.webp&w=3840&q=75)
The Role of the Security Expert During the Cognitive Revolution
Code is cheap. What does that mean for security experts? AISLE's AI researcher Dmitrijs Trizna weighs in.

AISLE Finds FreeBSD setuid-root Stack Buffer Overflows in ping6, libnv, and libcasper
AISLE discovers three FreeBSD stack buffer overflows, including a setuid-root ping6 path that creates a local privilege escalation primitive.

GitHub Got Hacked. The AI Security Arms Race is Here
The world's most popular forge has been hacked. Here's what that means for AI security — and what you can do to keep up.

AISLE Discovered 5 CVEs in curl. Now curl Uses Our AI to Secure Its Code
Why curl closed its bug bounty and adopted AISLE to secure its codebase - and what happened in the months that followed.

AISLE Discovers CVE-2026-42511: a 21-Year-Old FreeBSD Remote Command Execution Vulnerability
Learn how AISLE discovered a command injection to root RCE vulnerability in FreeBSD.

AISLE Discovers 3 Critical Vulnerabilities in FreeBSD
How AISLE’s multi-model AI system found critical security issues in one of the world's most trusted operating systems.

AISLE matches Anthropic Mythos on FreeBSD zero-days
AISLE matched Mythos with 3 FreeBSD zero-days in April 2026, including 2 remotely exploitable dhclient bugs, using much cheaper models.

Discovering 9 DoS Vulnerabilities in Elastic Beats
AISLE found nine High-severity DoS vulnerabilities in Elastic Beats, affecting Packetbeat, Filebeat, and Metricbeat parsers used in critical logging and observability pipelines.

Finding and Fixing 24 CVEs in WeKan with AISLE's Analyzer
AISLE found 24 Wekan CVEs, including three Critical flaws, across authorization bypass, IDOR, admin-check failures, leaks, and LDAP injection.
.webp&w=3840&q=75)
AISLE Discovers 38 CVEs in Healthcare Software Used by 100,000 Medical Providers
38 zero-day security vulnerabilities, three critical, and the shift from disclosure to prevention in healthcare software

AISLE Discovers 20 OpenSSL Zero-Days in 6 Months
On April 7, 2026, OpenSSL, the cryptographic backbone of the internet, published a security advisory patching 7 new security vulnerabilities.

AISLE Uncovered 5 of 7 OpenSSL Vulnerabilities in the April 2026 Release
AISLE's autonomous system discovered 5 of the 7 OpenSSL vulnerabilities fixed in the OpenSSL 3.5.6 and 4.0.0 releases.

System Over Model: Zero-Day Discovery at the Jagged Frontier
Here's how AISLE's autonomous system used small, cheap models to surface real zero-days in the FreeBSD kernel - and what that means for AI security.

AI Cybersecurity After Mythos: The Jagged Frontier
When AISLE tested Mythos's showcase vulnerabilities on small, cheap, open-weights models, most found the same bugs. Here's what that means for cyber.

OpenSIPS SQL Injection to Full Authentication Bypass (CVE-2026-25554)
The AISLE analyzer discovered a high-severity vulnerability that enables SQL injection in OpenSIPS, a pillar of global communications used by over ...

How AISLE is helping secure critical open source projects
AI is accelerating vulnerability discovery for attackers and defenders alike. AISLE helps maintainers stay ahead by catching issues before code ships.

AISLE discovers CVE-2026-22695: libpng buffer over-read
A few days ago, we released AISLE PRO, our developer-friendly GitHub PR analyzer that analyzes changes in the source code of a repository in pull r...

Using AISLE to Find Vulnerabilities in Amazon's Crypto Stack: AWS-LC and s2n-tls
AISLE has discovered vulnerabilities in Amazon's crypto stack. This post covers those vulnerabilities, following our findings in OpenSSL.

Firefox WebRTC GMP H.264 heap overflow via short EncodedImage (CVE-2026-2757)
AISLE's autonomous security analyzer discovered a buffer overflow vulnerability in Mozilla's WebRTC that affected both Firefox and Thunderbird, the...

How AISLE Unifies Detection and Remediation at Scale
A case of context-engineering agent workflow for CVE-2021-32804: collect exploit intelligence, run reachability analysis, and ship a tested patch.

CVE-2025-11187: OpenSSL PKCS#12 Stack Overflow & DoS
Deep dive into OpenSSL CVE-2025-11187: PBMAC1 PKCS#12 MAC validation bug causing stack overflow/NULL deref and the fix.
-1.webp&w=3840&q=75)
AISLE Becomes the #1 Source for OpenClaw Security Disclosures
AISLE is the largest source of security findings in OpenClaw, exposing risks in AI agents with shell access, file system control, and API keys to y...

What AI Security Research Looks Like When It Works
What a year of finding zero-days in OpenSSL, curl, and the Linux kernel taught us about AI-driven security research done right.

The Notepad++ Supply Chain Breach: Technical Overview and Response for the Chrysalis Backdoor
Notepad++ update hijack delivered the Chrysalis backdoor. Learn what happened, key IOCs, and KQL hunts to detect and respond.

OpenSSL Stack Overflow: CVE-2025-15467 Deep Dive
CVE-2025-15467 is a stack buffer overflow in CMS message parsing, and it has the potential to enable remote code execution under specific conditions.
AISLE Discovered 12 out of 12 OpenSSL Vulnerabilities
AISLE's autonomous analyzer found all 12 CVEs in the January 2026 coordinated release of OpenSSL, the open-source cryptographic library that underp...

Firefox / WebRTC Encoded Transforms: UAF via undetached ArrayBuffer / CVE-2025-14321
The AISLE Research Team discovered a use-after-free (UAF) vulnerability in Firefox's WebRTC API, namely in its WebRTC Encoded Transforms mechanism,...

How One Image Can Break Signal
Stanislav Fort, Aisle Research · December 2025

CVE-2025-66491: Traefik's "Verify=On" Turned TLS Off
Learn how CVE-2025-66491 exposed a critical TLS verification flaw in Traefik, where "Verify=On" accidentally disabled security for 5 months.

CVE-2025-12443: Chrome WebXR Flaw Hits 4 Billion Devices
Aisle Research discovers a memory disclosure vulnerability in Chromium's WebXR implementation, affecting over 4 billion devices across Chrome, Edge, Brave, and the entire Chromium ecosystem.

Command Injection in NASA CryptoLib (CVE-2025-59534)
NASA's CryptoLib had a critical 3-year-old authentication flaw. AISLE's AI detected it and helped ship CVE-2025-59534 fix in just 4 days.
.webp&w=3840&q=75)
A High-Severity WebAssembly Boundary Condition Vulnerability in Firefox: CVE-2025-13016
Discover how a single line of faulty pointer arithmetic in Firefox's WebAssembly engine created CVE-2025-13016, affecting 180M+ users.

How AISLE's Autonomous Analyzer Found Command Injection in glob's CLI (10M+ Weekly Downloads)
AISLE's AI discovered CVE-2025-64756, a critical command injection vulnerability in glob's CLI affecting 10M+ weekly downloads and CI pipelines.

CVE-2025-10230: The CVSS 10.0 Vulnerability That Hid in Samba for 13 Years
Critical Samba CVE-2025-10230 with CVSS 10.0 score lay hidden for 13 years before AISLE's discovery. Learn about this infrastructure threat.

AISLE Discovers Three of the Four OpenSSL Vulnerabilities of 2025!
AISLE's autonomous AI discovered 3 of 4 OpenSSL vulnerabilities in 2025, securing the cryptographic library protecting most internet traffic.

Accelerating to Zero: The Future of Vulnerability Management
We're making what seemed impossible, possible: zero vulnerabilities.
