Blog

Six Vulnerabilities in curl After Frontier AI Labs Came Back Empty thumbnail

AISLE Discovered Six curl CVEs After OpenAI and Anthropic Found Zero

After frontier AI systems came up empty, AISLE surfaced six CVEs in curl, one of the world's most audited codebases. Its maintainers patched all six.

Stanislav FortSeptember 2, 2026
old photographs representing long-hidden vulnerabilities

AISLE Discovers 6 High and Critical CVEs in FFmpeg

AISLE's AI-native engine found six high and critical CVEs in FFmpeg, including a 9.8 remote heap overflow and a stack overflow that survived 19 years.

AISLE Research Team August 27, 2026
an image of fibers in AISLE style

Attackers Are Using AI to Find Vulnerabilities in Your Code. Your SAST Was Never Even Looking for Them

Can AI-native code analysis replace SAST, or is it just a complement. Here's what data from real-world results shows.

Ondrej VlcekAugust 12, 2026
Keeping FFmpeg secure

AISLE Finds 21 Security Issues in FFmpeg, Including 6 New CVEs

AISLE uncovered 21 issues in FFmpeg, including 6 new CVEs spanning code execution and out-of-bounds reads. All patched, with commit links inside.

AISLE Research Team August 5, 2026
Cursor blog hero image

AISLE Discovers a One-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity

Learn how our AI found a one-click RCE vulnerability in 3 code editors: Cursor, VS Code, and Google Antigravity.

Stanislav FortJuly 31, 2026
an image of a trojan horse

The Model That Fixes Your Code Might Hack the Linux Kernel

Learn how easy it is to trojanize a model, and what defenders can do to protect their supply chains from this emerging threat.

Patrik MadaJuly 28, 2026
a vein of gold in AISLE style

The Economics of Security Vulnerabilities: Why Discovery Is Not Commoditizing

If discovery is cheap, why are people willing to pay more for exploits than ever before? Here's what the market for exploits shows.

Ondrej VlcekJuly 23, 2026
a stylized representation of databases

AISLE Finds 8 CVEs Across MySQL, MariaDB, and PostgreSQL

Learn how AISLE found 8 CVEs in critical databases using autonomous, AI-native analysis and verification.

AISLE Research Team July 7, 2026
fiery curl in AISLE style

AISLE Discovers 6 New CVEs in curl, Including the Oldest Issue Ever Reported

AISLE's analyzer discovered 6 new CVEs in curl, more than 2x the nearest AI security platform and including the oldest security issue in the project.

AISLE Research Team June 24, 2026
an abstract image of a trophy for aisle

AISLE Won a Hacker News Cybersecurity Stars Award. Here's What It Means.

AISLE was named Most Innovative AI-Powered Vulnerability Management Platform by The Hacker News at the inaugural Star Awards. Here's why.

AISLEJune 17, 2026
Mythos at home blog thumbnail

"Mythos" at Home, and It's Called AISLE

A startup out of Europe built an AI system that matches Mythos on zero-day discovery, using widely available models, even air-gapped.

Stanislav FortJune 17, 2026
Spotlight keeping us safe

Control Is the New Frontier in Security AI

Frontier AI can vanish overnight. For security teams, control is a requirement, not a luxury. Why sovereign AI is the new frontier in cyber defense.

Ondrej VlcekJune 14, 2026
a giant phantom zero

Your Security Shouldn't Depend on Someone Else's API

Why the historical tension between frontier capability and full sovereignty is dissolving, and why deployment-agnostic AI security is the answer.

Ondrej VlcekJune 11, 2026
An abstract image of bright lines rushing towards the horizon

Announcing AISLE Snapshot: Rapid AI Code Analysis for Every Environment

Introducing AISLE Snapshot, the rapid AI code audit that delivers frontier-class security findings to air-gapped, on-prem, and cloud environments.

AISLEJune 10, 2026
a chip in an embedded device with light coming from it

AISLE Finds 4 CVEs in One of the World’s Most Popular IoT Platforms

Learn how AISLE's analyzer agents found four CVEs in one of the world's most popular embedded platforms.

AISLE Research Team June 9, 2026
Security researcher speaking on stage

The Role of the Security Expert During the Cognitive Revolution

Code is cheap. What does that mean for security experts? AISLE's AI researcher Dmitrijs Trizna weighs in.

Dmitrijs TriznaMay 26, 2026
freebsd ping6

AISLE Finds FreeBSD setuid-root Stack Buffer Overflows in ping6, libnv, and libcasper

AISLE discovers three FreeBSD stack buffer overflows, including a setuid-root ping6 path that creates a local privilege escalation primitive.

AISLE Research Team May 25, 2026
Water drop creating a ripple effect

GitHub Got Hacked. The AI Security Arms Race is Here

The world's most popular forge has been hacked. Here's what that means for AI security — and what you can do to keep up.

Joshua RogersMay 21, 2026
AISLE curl CVE findings and partnership

AISLE Discovered 5 CVEs in curl. Now curl Uses Our AI to Secure Its Code

Why curl closed its bug bounty and adopted AISLE to secure its codebase - and what happened in the months that followed.

AISLE Research Team May 13, 2026
FreeBSD 2

AISLE Discovers CVE-2026-42511: a 21-Year-Old FreeBSD Remote Command Execution Vulnerability

Learn how AISLE discovered a command injection to root RCE vulnerability in FreeBSD.

AISLE Research Team May 7, 2026
FreeBSD 1

AISLE Discovers 3 Critical Vulnerabilities in FreeBSD

How AISLE’s multi-model AI system found critical security issues in one of the world's most trusted operating systems.

AISLE Research Team May 7, 2026
AISLE and Mythos.

AISLE matches Anthropic Mythos on FreeBSD zero-days

AISLE matched Mythos with 3 FreeBSD zero-days in April 2026, including 2 remotely exploitable dhclient bugs, using much cheaper models.

Stanislav FortMay 6, 2026
Elastic Beats

Discovering 9 DoS Vulnerabilities in Elastic Beats

AISLE found nine High-severity DoS vulnerabilities in Elastic Beats, affecting Packetbeat, Filebeat, and Metricbeat parsers used in critical logging and observability pipelines.

AISLE Research Team April 30, 2026
Wekan

Finding and Fixing 24 CVEs in WeKan with AISLE's Analyzer

AISLE found 24 Wekan CVEs, including three Critical flaws, across authorization bypass, IDOR, admin-check failures, leaks, and LDAP injection.

AISLE Research Team April 29, 2026
OpenEMR - blog hero (1)

AISLE Discovers 38 CVEs in Healthcare Software Used by 100,000 Medical Providers

38 zero-day security vulnerabilities, three critical, and the shift from disclosure to prevention in healthcare software

AISLE Research Team April 28, 2026
aisle-discovers-20-openssl-zero-days-in-6-months

AISLE Discovers 20 OpenSSL Zero-Days in 6 Months

On April 7, 2026, OpenSSL, the cryptographic backbone of the internet, published a security advisory patching 7 new security vulnerabilities.

Stanislav FortApril 24, 2026
OpenSSL

AISLE Uncovered 5 of 7 OpenSSL Vulnerabilities in the April 2026 Release

AISLE's autonomous system discovered 5 of the 7 OpenSSL vulnerabilities fixed in the OpenSSL 3.5.6 and 4.0.0 releases.

AISLE Research Team April 23, 2026
Eye visual for blog_1.

System Over Model: Zero-Day Discovery at the Jagged Frontier

Here's how AISLE's autonomous system used small, cheap models to surface real zero-days in the FreeBSD kernel - and what that means for AI security.

Stanislav FortApril 14, 2026
mythos2

AI Cybersecurity After Mythos: The Jagged Frontier

When AISLE tested Mythos's showcase vulnerabilities on small, cheap, open-weights models, most found the same bugs. Here's what that means for cyber.

Stanislav FortApril 7, 2026
OpenSIPS vulnerability

OpenSIPS SQL Injection to Full Authentication Bypass (CVE-2026-25554)

The AISLE analyzer discovered a high-severity vulnerability that enables SQL injection in OpenSIPS, a pillar of global communications used by over ...

AISLE Research Team March 19, 2026
ondrej

How AISLE is helping secure critical open source projects

AI is accelerating vulnerability discovery for attackers and defenders alike. AISLE helps maintainers stay ahead by catching issues before code ships.

Ondrej VlcekMarch 11, 2026
libpng vulnerability

AISLE discovers CVE-2026-22695: libpng buffer over-read

A few days ago, we released AISLE PRO, our developer-friendly GitHub PR analyzer that analyzes changes in the source code of a repository in pull r...

AISLE Research Team March 6, 2026
amazon crypto vulnerability findings

Using AISLE to Find Vulnerabilities in Amazon's Crypto Stack: AWS-LC and s2n-tls

AISLE has discovered vulnerabilities in Amazon's crypto stack. This post covers those vulnerabilities, following our findings in OpenSSL.

Joshua RogersMarch 3, 2026
Firefox CVE-2026-2757

Firefox WebRTC GMP H.264 heap overflow via short EncodedImage (CVE-2026-2757)

AISLE's autonomous security analyzer discovered a buffer overflow vulnerability in Mozilla's WebRTC that affected both Firefox and Thunderbird, the...

AISLE Research Team February 25, 2026
AI Context Engineering

How AISLE Unifies Detection and Remediation at Scale

A case of context-engineering agent workflow for CVE-2021-32804: collect exploit intelligence, run reachability analysis, and ship a tested patch.

AISLE Research Team February 24, 2026
OpenSSL CVE-2025-11187

CVE-2025-11187: OpenSSL PKCS#12 Stack Overflow & DoS

Deep dive into OpenSSL CVE-2025-11187: PBMAC1 PKCS#12 MAC validation bug causing stack overflow/NULL deref and the fix.

AISLE Research Team February 24, 2026
openclaw

AISLE Becomes the #1 Source for OpenClaw Security Disclosures

AISLE is the largest source of security findings in OpenClaw, exposing risks in AI agents with shell access, file system control, and API keys to y...

Stanislav FortFebruary 15, 2026
AISLE Founders

What AI Security Research Looks Like When It Works

What a year of finding zero-days in OpenSSL, curl, and the Linux kernel taught us about AI-driven security research done right.

Stanislav FortFebruary 8, 2026
Notepad++

The Notepad++ Supply Chain Breach: Technical Overview and Response for the Chrysalis Backdoor

Notepad++ update hijack delivered the Chrysalis backdoor. Learn what happened, key IOCs, and KQL hunts to detect and respond.

AISLE Research Team February 4, 2026
Server room

OpenSSL Stack Overflow: CVE-2025-15467 Deep Dive

CVE-2025-15467 is a stack buffer overflow in CMS message parsing, and it has the potential to enable remote code execution under specific conditions.

AISLE Research Team February 4, 2026
openssl-2

AISLE Discovered 12 out of 12 OpenSSL Vulnerabilities

AISLE's autonomous analyzer found all 12 CVEs in the January 2026 coordinated release of OpenSSL, the open-source cryptographic library that underp...

AISLE Research Team January 26, 2026
ff-webtrc-clean

Firefox / WebRTC Encoded Transforms: UAF via undetached ArrayBuffer / CVE-2025-14321

The AISLE Research Team discovered a use-after-free (UAF) vulnerability in Firefox's WebRTC API, namely in its WebRTC Encoded Transforms mechanism,...

AISLE Research Team January 21, 2026
signal-bg

How One Image Can Break Signal

Stanislav Fort, Aisle Research · December 2025

Stanislav FortDecember 14, 2025
traefik-bg

CVE-2025-66491: Traefik's "Verify=On" Turned TLS Off

Learn how CVE-2025-66491 exposed a critical TLS verification flaw in Traefik, where "Verify=On" accidentally disabled security for 5 months.

AISLE Research Team December 9, 2025
chromium

CVE-2025-12443: Chrome WebXR Flaw Hits 4 Billion Devices

Aisle Research discovers a memory disclosure vulnerability in Chromium's WebXR implementation, affecting over 4 billion devices across Chrome, Edge, Brave, and the entire Chromium ecosystem.

Stanislav FortDecember 3, 2025
nasa-image

Command Injection in NASA CryptoLib (CVE-2025-59534)

NASA's CryptoLib had a critical 3-year-old authentication flaw. AISLE's AI detected it and helped ship CVE-2025-59534 fix in just 4 days.

AISLE Research Team November 27, 2025
firefox-blog

A High-Severity WebAssembly Boundary Condition Vulnerability in Firefox: CVE-2025-13016

Discover how a single line of faulty pointer arithmetic in Firefox's WebAssembly engine created CVE-2025-13016, affecting 180M+ users.

AISLE Research Team November 24, 2025
glob-blog-post

How AISLE's Autonomous Analyzer Found Command Injection in glob's CLI (10M+ Weekly Downloads)

AISLE's AI discovered CVE-2025-64756, a critical command injection vulnerability in glob's CLI affecting 10M+ weekly downloads and CI pipelines.

AISLE Research Team November 18, 2025
The CVSS 10.0 Vulnerability That Hid in Samba for 13

CVE-2025-10230: The CVSS 10.0 Vulnerability That Hid in Samba for 13 Years

Critical Samba CVE-2025-10230 with CVSS 10.0 score lay hidden for 13 years before AISLE's discovery. Learn about this infrastructure threat.

AISLE Research Team November 7, 2025
aisle dark room placeholder

AISLE Discovers Three of the Four OpenSSL Vulnerabilities of 2025!

AISLE's autonomous AI discovered 3 of 4 OpenSSL vulnerabilities in 2025, securing the cryptographic library protecting most internet traffic.

AISLE Research Team October 29, 2025
AISLE Founders

Accelerating to Zero: The Future of Vulnerability Management

We're making what seemed impossible, possible: zero vulnerabilities.

Ondrej VlcekOctober 16, 2025