Loading video...

Video Failed to Load

Go Home

GPT-5.6 Sol Ultra autonomously build a full Chrome renderer exploit chain and pop calc.exe, in a days. AI go from V8 source a7 recent security fixes to a complete sandbox escape & code execution with minimal guidance, Maglev type confusion, forged primitives, NativeModule UAF, Wasm pointer hijacking the whole...

21,010 views • 1 month ago •via X (Twitter)

0 Comments

No comments available

Comments from the original post will appear here

Related Videos

🦔 Google Chrome is launching "autobrowsing" today for paid subscribers. Instead of just autofilling your credit card, Chrome will now complete entire tasks for you: filling out PDFs, renewing your driver's license, researching trips, booking reservations. You give it a task, it browses the web autonomously, and asks for your approval at the final step. Available for Google AI Pro ($19.99/month) or AI Ultra ($249.99/month). All Chrome users get a new Gemini AI sidebar that pulls from your Gmail and past conversations. My Take Last week Google announced AI Mode connecting to your Gmail and Photos. Now Chrome is pulling from your emails, conversations, and browsing activity to act on your behalf. Every new AI feature requires deeper access to your personal data. You're not just paying $20 or $250 a month for convenience. You're handing over your credit cards, government documents, addresses, and browsing habits to an AI that will interact with websites as you. The people excited about this haven't thought through what happens when it goes wrong. An AI filling out government forms. An AI with your credit card making purchases. An AI that hallucinates or gets social engineered. And when adoption isn't fast enough, they'll degrade regular search and browsing until this feels like the only viable option. That's the playbook. Meanwhile $250 a month tells you exactly how much this costs them to run, and how desperate they are to find someone willing to pay for it. Hedgie🤗

Hedgie

11,662 views • 7 months ago

The corporate system wants you trading time for a paycheck. The alternative is building automated leverage. You do not need a team of engineers. You just need the right open-source architecture. Here are 10 GitHub repos to automate your workflows, replace manual labor, and direct your own reality: 1. n8n Bypass expensive SaaS subscriptions. Build custom AI automation workflows that run on your own servers. 2. Ollama Stop sending your private data to massive API providers. Run heavy AI models locally on your own machine. Complete privacy. 3. Open Interpreter Let language models control your computer. Automate the repetitive corporate tasks they pay you to do manually. 4. Aider An AI pair programmer that lives in your terminal. Stop writing boilerplate code and focus strictly on the architecture. 5. Dify An open-source LLM app development platform. Build and deploy functional AI agents in minutes, not months. 6. Flowise A drag-and-drop UI to build customized LLM flows. You do not need to be a senior developer to build massive leverage. 7. Supabase Spin up a Postgres database, authentication, and instant APIs. Own your backend entirely. 8. Auto-GPT Give an AI an objective and let it execute. It browses the web, writes code, and chains thoughts together autonomously. 9. Outline An open-source knowledge base for your personal leverage. Stop losing your documentation in arbitrary corporate systems. 10. NocoDB Turn any database into a smart spreadsheet. Keep your data on your own infrastructure and stop paying for convenience. The secret to tech survival? Stop playing by their rules. Build your own systems and take your leverage with you.

Katyayani Shukla

16,964 views • 4 months ago

GPT 5.6 Sol just saved me €650 a year and demonstrated just how good this model is as an agent in @ChatGPTapp Codex. This is not a clickbait, let me explain. In France, insurance companies tend to hide all their prices behind quote forms that take at least 5min to complete for a single configuration on a single provider's website. And that take an other 5min to understand. If you want to compare 10 companies across 5 configurations each, it takes at least 4h +. (It's such a painful process that entire businesses exist just to compare insurance offers.) Since I have two cars, it would normally take me 8h so an entire day to have a real large view of my best option. Companies know this and use the friction to maintain overpriced offers. So I asked @ChatGPTapp with GPT 5.6 Sol, using Chrome tabs, to go through all those annoying forms. I provided him all my contrats with my current insurance companies so he have context. For some insurers, you even have to speak with a representative just to get a quote (which is absurd in 2026), so it emailed the companies, exchanged the required information, and obtained the prices. It then ran a complete benchmark, read all the terms and conditions, and recommended three options from three different companies. I picked one, and it completed the subscription with my new insurance company. And that's how I ended up with better insurance coverage for less money. For 4% of my weekly quota in 20x plan. (i think it's fair) All of that happened while I was walking my dog for 50 minutes, he was working on my computer all by it's on. Yes, computer use existed before OpenAI GPT 5.6 Sol, but this is a completely different level in the way it handles these kinds of tasks. I think this story shows the new era of AI we're entering, good model is not only for one single task as coding or answering question, AI now can do things for you, like in your daily live. I love being able to hand my computer over to GPT 5.6 Sol. PS: The only annoying part was that some companies still require "Verify you're human" checks. In the age of AI agents, websites really need to be ready for robot access.

Defend Intelligence (Anis Ayari)

78,505 views • 1 month ago

Google just confirmed the first case of hackers using AI to build a zero-day exploit from scratch. An actual zero-day vulnerability that no human had EVER found before, discovered by an AI model, turned into a working weapon, and aimed at a mass exploitation campaign targeting thousands of systems simultaneously. Google's Threat Intelligence Group caught it yesterday and killed the operation before it scaled. But the details of how it worked are genuinely scary: The AI found a flaw in a popular two-factor authentication system that traditional security tools had missed entirely. The vulnerability was a logic error buried deep in the authentication flow where a developer had hard-coded a trust exception years ago. No human security researcher or automated scanner had caught it. The flaw was invisible to EVERY tool the cybersecurity industry has built over the past two decades. But the AI spotted it immediately. Then it wrote a full Python exploit script to weaponize it. Google's analysts could tell the code was AI-generated because it had textbook formatting, educational comments explaining every function, and even a hallucinated severity score that doesn't exist in any real database. The AI literally graded its own attack with a fake rating. So the code had MISTAKES in it. The criminals' implementation was clumsy enough that it probably interfered with the actual deployment. This was the sloppy first attempt by people who are still learning how to use these tools. And it still found a vulnerability that the entire cybersecurity industry missed. Google's chief threat analyst John Hultquist said: "There's a misconception that the AI vulnerability race is imminent. The reality is that it's already begun. For every zero-day we can trace back to AI, there are probably many more out there." But here's where it gets truly insane... This wasn't even a sophisticated operation. North Korea's APT45 hacking unit is sending thousands of repetitive prompts to AI models, recursively analyzing known vulnerabilities and building an entire exploit arsenal that would be physically impossible for human hackers to assemble at the same speed. They're essentially industrializing cyberattacks. A Chinese state-linked group jailbroke Google's own Gemini by simply asking it to "pretend to be a network security expert" and then used that persona to research how to hack TP-Link routers and corporate file transfer systems. Another Chinese group deployed autonomous AI agents that probed a Japanese tech firm with minimal human oversight, deciding on their own which tools to use and pivoting between targets based on internal reasoning. And then there's PROMPTSPY, an Android backdoor that calls Google's Gemini API to read your phone screen in real time, navigate your interface autonomously, capture your biometric data, replay your lock screen PIN, and block you from uninstalling it by placing an invisible overlay over the uninstall button. It literally OPERATES your phone using commercial AI tools anyone can access. Everyone spent the last 3 years arguing about whether AI would take people's jobs. Meanwhile AI is making every password, every firewall, and every two-factor authentication system on Earth fundamentally less secure. The entire $190 billion cybersecurity industry was built on one assumption: that finding vulnerabilities is hard and requires deep expertise. But AI just removed that assumption from the equation. And the scariest part is that Google said the criminals made errors this time. The implementation was rough and the campaign probably didn't fully work. These were amateurs, now imagine what professionals are able to do. There's a reason Sam Altman predicted an inevitable massive cyberattack THIS year. What do you think?

Ricardo

50,564 views • 3 months ago

Biggest announcement of my life: I have raised pre-seed funding from 021T, Dr. Alex Wissner-Gross , and Devon Triplett to build an AI agent that will change the world The biggest issue with AI is it is creating incredible value but for only a small group of people Most people hate AI and don't use it I have built Henry Intelligent Machines (HIM) to solve this HIM is a personal swarm of AI agents autonomously creating economic value for you 24/7 Right now as we speak HIM is collecting data across thousands of websites autonomously 24/7/365 They're hunting for challenges to solve at all times When you use Henry, he will deeply research you and get to know you. Then based on the thousands of opportunities it has in its database, find the value generating opportunities that most closely match your interests, skills, assets, and expertise Henry and its swarm will then proceed to build those micro-businesses out for you You will have complete control over the swarm. Reviewing and approving all work. Editing where you find appropriate. You give Henry a budget, then it hunts and autonomously creates value Say you have an expertise in vibe coding tools and Henry discovers there's no vibe coding guides on Gumroad. It will take your expertise, build drafts for a guide, run it by you, post with your approval, then use your budget to get customers Say you're into AI and speak Portuguese Henry will go through the Portuguese AI education market, see there are no educational products in that language, then create a full AI educational business in Portuguese Most people hate AI. This is because they get 0 value from it, see their friends getting laid off, and become scared HIM is the antidote to this. HIM allows ANYONE to get value from AI. HIM will allow anyone to get access to the trillions of dollars of value that are up for grabs in the new AI world. To ensure Henry creates value and not slop, this will be an extremely slow rollout We will be letting people into HIM 1 by 1. Working with them hands on to ensure Henry only builds real value for them, then expanding from there. If you'd like to be one of the early users of Henry, feel free to sign up at the link below. Forward.

Alex Finn

478,595 views • 4 months ago

🚨APPLE SPENT 5 YEARS AND BILLIONS OF DOLLARS BUILDING THE MOST ADVANCED SECURITY SYSTEM IN CONSUMER HISTORY.. AN AI BROKE IT IN 5 DAYS.. Here’s what just happened.. Apple built something called Memory Integrity Enforcement for its new M5 chips.. It’s a hardware-level security system that attaches secret cryptographic tags to every piece of memory.. If a hacker tries to access memory they shouldn’t.. The chip blocks it instantly.. Every known exploit chain against iOS and macOS was rendered obsolete overnight.. Apple said so themselves.. Then a small team at a cybersecurity firm called Calif used Anthropic’s unreleased Claude Mythos Preview to find vulnerabilities in the macOS kernel.. The AI found the bugs almost instantly.. Because once it learned the pattern of a specific type of flaw.. It could recognize every other flaw in that same class across the entire codebase.. What used to take elite security teams months.. The AI did in hours.. Within 5 days.. The team had a fully working exploit that escalated a basic user account to full root access on an M5 Mac running the latest macOS.. With MIE fully enabled.. The billion-dollar hardware defense running at full strength.. The trick.. They didn’t fight the hardware.. They went around it.. MIE is designed to catch memory corruption.. Hackers trying to overwrite pointers or inject code.. The team used a “data-only” approach instead.. They manipulated legitimate data structures the hardware was never designed to monitor.. Like changing an internal flag from “standard user” to “admin”.. The chip saw a perfectly normal operation.. The operating system obeyed.. And the attacker had total control.. The hardware thought everything was fine.. Because technically it was.. The exploit never triggered a single tag mismatch.. They walked into Apple Park and hand-delivered a 55-page report.. Apple patched it in macOS 26.5.. And for the first time ever.. Apple’s official security advisory credited the vulnerability discovery to “Calif dot io in collaboration with Claude and Anthropic Research”.. An AI is now credited in Apple’s CVE patches.. But here’s what makes this story truly terrifying.. Before MIE existed.. An exploit kit called DarkSword was hitting iPhones with zero-click attacks.. Six vulnerabilities chained together.. Total device control just from visiting a webpage.. Deployed by Russian espionage groups, Turkish surveillance vendors, and actors in Saudi Arabia.. Then it got leaked on GitHub.. Nation-state capabilities.. Free for anyone.. MIE was supposed to make all of that impossible.. And an AI found a way around it in 5 days.. The previous model.. Claude Opus 4.6.. Found 22 security bugs in the Firefox codebase.. Claude Mythos Preview found 271 in the same environment.. A tenfold increase.. Linux kernel CVEs jumped from 300 per year to over 5,500.. Largely driven by AI-powered vulnerability research.. The IMF designated Claude Mythos as a systemic financial stability risk.. Because if an AI finds a flaw in software used by every major bank simultaneously.. It could trigger a cascading financial crisis.. Anthropic knew this was coming.. That’s why they didn’t release the model publicly.. Instead they launched Project Glasswing.. Giving defensive access to AWS, Apple, Google, Microsoft, Nvidia, CrowdStrike, JPMorgan, and others.. $100 million in usage credits.. So defenders can scan their own systems before attackers get this capability.. The Pentagon blacklisted Anthropic over autonomous weapons.. Then quietly started using Mythos to harden government systems anyway.. The cybersecurity arms race just changed permanently.. Hardware can’t save you.. Software can’t save you.. The only defense against an AI that finds vulnerabilities is another AI that finds them first.. Five years and billions of dollars.. Five days and one AI.

Evan Luthra

91,160 views • 3 months ago

(4 DAYS BEFORE SUBMISSIONS CLOSE) I get this question a lot about the Find Evil! hackathon: What does “find evil” actually mean? In this case, the name comes from a real command. I built an autonomous incident response agent I built on the SIFT Workstation. Then I typed “find evil” as a prompt into Claude Code. And it did (watch the demo). I was blown away to watch the autonomous agent run a complete C drive forensic analysis, across 200+ tools via MCP. The agent identified threat actor and context, the attack chain, malware deployment method, persistence mechanisms, code injection analysis, network connections, command-and-control (C2) infrastructure, a complete malicious process tree, and a chronological activity timeline. Two days after I shared initial findings, Anthropic released their report on how threat actors were deploying Claude Code with operational tools and letting it go do evil. (Same thing I was doing.) Find Evil! is the first hackathon dedicated to building autonomous AI agents for incident response. 4,178 defenders are working on final Find Evil! hackathon submits. (This number makes me very happy to see so many diving in. And wishing that the thousands more in our community were experimenting with us.) Your job: teach an AI agent to think like a senior analyst, how to sequence its approach, recognize when something doesn’t add up, and self-correct when it gets it wrong. There are FOUR DAYS left to build with us! (Very few of us are actual AI experts. The rest of us including me are learning.) Register: Apply to judge: We need DFIR, AI, cybersecurity, and open-source reviewers who can separate useful autonomous response tools from polished demos. Apply: I am SO EXCITED to see what comes out of this hackathon and goes back to the community. Sponsored by SANS Institute

Rob T. Lee

14,405 views • 2 months ago

Here we go again 🚀! Excited to announce that we're building A1Zap (YC W25) with Pennie Li and that we're in the Y Combinator W25 batch in San Francisco! What is A1Base? A1Base gives AI Agents a real world identity for work. We do that by rebuilding Twilio and Okta from the ground up, putting AI Agents first. This means developers can make AI-first agentic applications 10x easier with our API's. ⁉️ Why are we doing this? Because there's a huge torrent of new valuable companies possible with AI agents, but to get their AI Agents to users, they have to chain custom apps, chat interfaces, awkward Slack integrations, browser bots, and wrestle with Twilio’s legacy API (which is built for marketing). We solve this by providing developers with an easy to use API to interface your AI agent with humans/coworkers/users where they are in this case in Whatsapp, Slack, Teams, SMS and more) - with AI Agent features built in. These digital workers are poised to transform how we work and we're the critical infrastructure to help them interact naturally in human workflows. We're not just building another AI tool. We're creating the infrastructure that will enable AI agents to become a natural part of the workforce - handling everything from customer support to sales development to creative work. We're backed by Y Combinator and working with founding teams who share our vision. We believe that in the near future, AI Agents with human coworkers will enable us to pursue more creative and impactful work. Our mission is to help developers build AI Agents that people can partner with and rely on as trusted allies—always with a human-first mindset. If you're thinking about the Agentic future of your company reach out! If you're looking to build your first AI Agentic company - reach out too - we have some amazing open source templates to get you started on the journey. Excited to share more of what we're up to soon 🔜.

Pasha Rayan

53,950 views • 1 year ago

Everyone told Vicente Silveira (Vicente Silveira) that his startup—a GPT wrapper—would fail. Instead, one year later, it’s thriving—with about 500,000 registered users, nearly 3,000 paying subscribers, and over 2 million conversations in the GPT store. Vicente is the cofounder and CEO of AI PDF, a tool that can help you summarize, chat with, and organize your PDF files. When OpenAI allowed users to upload PDFs to @ChatGPTapp, the consensus was that his startup, and all the other GPT wrappers out there, were toast. Some of his competitors even shut shop, but Vicente believed they could still create value for users as a specialized tool. The AI PDF team kept building. A year later, AI PDF is one of the most popular AI-powered PDF readers in the world—and they did it all with a five-person team, and a friends and family round. I sat down with Vicente to understand, in granular detail, the success of AI PDF. We get into: - Why staying small and specialized is a bigger advantage than you think - The power of building with your early adopters - Why lean startups are better positioned than frontier AI companies to create radical solutions - When a growing startup should think about raising venture capital - The emerging role of ‘AI managers’ who will be responsible for overseeing AI agents We even demo an agent integrated into AI PDF, prompting it to analyze recent articles from my column Chain of Thought and write a bulleted list of the core thesis statements. This is a must-watch for small teams building profitable companies at the bleeding edge of AI. Watch below! Timestamps: Introduction: 00:00:35 AI PDF’s story begins with an email to OpenAI’s Greg Brockman: 00:02:58 Why users choose AI PDF over ChatGPT: 00:05:41 How to compete—and thrive—as a GPT wrapper: 00:06:58 Why building with early adopters is key: 00:20:49 Being small and specialized is your biggest advantage: 00:27:53 When should AI startups raise capital: 00:31:47 The emerging role of humans who will manage AI agents: 00:34:53 Why AI is different from other tech revolutions: 00:45:25 A live demo of an agent integrated into AI PDF: 00:54:01

Dan Shipper 📧

25,628 views • 1 year ago

AI Digest No.72: When Deepfakes Escalate and AI Gets Closer Here are five stories shaping this week in AI: 🩺 ChatGPT Moves Into Healthcare OpenAI launched ChatGPT Health, allowing users to connect medical records for personalized insights. What looks like patient empowerment also raises hard questions about privacy, data security, and how much medical judgment should be delegated to AI. 🌍 Deepfakes Are Becoming a Geopolitical Weapon A Foreign Affairs analysis warns that deepfakes could destabilize global politics by fabricating evidence of attacks, manipulating elections, or triggering military escalation before verification is possible. 🤖 AI Assistants Start Acting on Our Behalf Lenovo revealed plans for an AI assistant that doesn’t just answer questions, but performs actions autonomously across devices and services. This marks a shift toward agentic AI systems that function as digital proxies, not just tools. 🏥 AI Quietly Reduces Emergency Room Waits In England, the NHS is using AI forecasting to predict emergency department demand and cut A&E waiting times. It’s a reminder that AI’s most meaningful impact often happens far from headlines. 🧍 Real Humans Push Back Against AI Content Floods As AI-generated content overwhelms social platforms, creators with authentic voices are gaining renewed traction. In a world of infinite generation, trust and originality are becoming the rarest assets online. Read the full digest on our Medium 👉

GT Protocol

33,187 views • 7 months ago

Anthropic admitted they built an AI so capable they were scared to release it and the number that explains why is 250. Anthropic's CFO Krishna Rao described in this clip what happened when they ran Mythos against an open source codebase that a previous frontier model had already analyzed. The prior model found 22 security vulnerabilities, Mythos found 250. In the same codebase, that the previous model had already reviewed and flagged as relatively clean. That number, more than 11 times as many vulnerabilities discovered is not just a benchmark improvement, it is a signal that there is an entire layer of software infrastructure that humanity has been operating under the assumption was secure and that assumption may no longer hold. The UK AI Security Institute independently evaluated Mythos Preview and confirmed what the internal numbers suggested. On expert level capture the flag challenges that no model could complete before April 2025, Mythos succeeded 73% of the time and it became the first model ever to complete a complex end-to-end attack range from start to finish, autonomously, without human guidance. The World Economic Forum called this a new security-driven era for AI, the Governor of the Bank of England publicly warned that Anthropic may have found a way to unlock the entire cyber-risk landscape, and the European Central Bank began quietly contacting financial institutions to assess their security posture. The response from Anthropic is what makes this story genuinely important. Rather than shelving the model or publishing it as a standard API release, Rao described a phased approach restricting access to a controlled group, focusing specifically on how the cyber capabilities can be used defensively rather than offensively and treating that framework as a template for how to release powerful but dangerous models in the future. The broader context makes that framing even more significant. AI generated code is already creating ten times more security vulnerabilities than human-written code, 63% of organizations reported experiencing an AI driven cyberattack in the past 12 months, and traditional signature-based security tools were built for a threat model that no longer describes the attack surface companies are defending against. Mythos represents a genuine leap in what autonomous security reasoning can do and it cuts both ways. The model that can find 250 vulnerabilities in a codebase a prior model rated as mostly clean is also, in the wrong hands, the model that can exploit those 250 vulnerabilities before a human defender has even finished reading the report. Anthropic's phased release strategy is not just a legal or PR decision, it is the most honest signal yet from a frontier lab that safety governance and capability development can no longer be treated as separate workstreams. The question is not whether this technology gets deployed, it is whether the institutions using it defensively stay ahead of the ones who will eventually use it offensively and whether the labs building it can keep those two timelines from inverting.

Milk Road AI

24,356 views • 3 months ago