
An AI agent built a working exploit for this macOS flaw in four hours
THE SO WHAT
An AI agent generating a working pre-auth root exploit in four hours turns zero-day development into a race you can’t win manually. Security leaders need to assume exploit availability shortly after disclosure — tighten patch SLAs, expand canary and anomaly detection, and treat LLM-accelerated offense as the new baseline.
READ THE SOURCE
MORE FROM THE WIRE
Applied AIGitHub disputes Wiz’s claim that Copilot Autofix wrote a Snowflake flaw
Blaming Copilot Autofix for Snowflake’s flaw collapsed under scrutiny, but the real story is now on the record: AI agents can already find and weaponize critical bugs. Security teams need to assume adversaries are running AI-first exploit pipelines and upgrade their own testing, code review, and red-teaming to match that tempo.
Applied AIQwen3.8-27B runs frontier-class coding agents and reasoning locally, no cloud API required
A 27B Qwen3.8-27B model running “frontier-class” coding and reasoning locally means high-end AI agents are no longer inherently a cloud product. If you’re building around OpenAI/Anthropic APIs, start a parallel track evaluating on-prem and hybrid options for cost, latency, and data control advantages.
Applied AIAnthropic’s annualized revenue surges to $65B
A $65B annualized run rate with $18B added in two months says the model layer is absorbing enterprise software budget at an unprecedented clip. If you sell into the same buyers, assume AI platform spend is now a primary line item and reposition your product either as an AI amplifier or as non-discretionary adjacent spend.
Applied AIGreg Brockman says OpenAI underestimated its own models’ cyber skills
When OpenAI’s president says they underestimated their models’ cyber capabilities, the bar for “dual-use” just moved. CISOs and infra teams should treat advanced LLM access like a privileged security tool—tighten controls, logging, and acceptable-use policies before those capabilities leak into routine workflows.