'KVM Chainsaw' Expected to Hit Linux 7.3 For Dealing with 'God Data Structure'
Read more of this story at Slashdot.
Read more of this story at Slashdot.
As AI-enabled hacking becomes a bigger threat for cybersecurity and national security, public attention has focused on mainly a few leading frontier AI companies developing more powerful large language models.
These models, and the billions of dollars behind them matter, but theyβre only part of a larger shift. Enterprises are now building their own technology platforms that take these general-purpose LLMs and turn them into bespoke cybersecurity tools.
Industry professionals refer to these tools as a βharness.βΒ They control the modelβs behavior, limit its risks, and connect itΒ to internal IT systems and networks so it can work reliably at scale.
New research from Cato Networks shared exclusively with CyberScoop shows how much power can come from a harness. It paired OpenAIβs ChatGPT 5.5 and GPT 5.5-Cyber models with its own tool and tested the abilities of the agent to hack into a victim network with as little human direction as possible.
Across six different scenarios, the pairing achieved complete end-to-end attack chains, including domain administrator privileges and Active Directory access, sometimes in as little as 40 minutes.
βWhat was most surprising is that first we saw that it was capable of doing accelerated reasoning and attack, and interacting and doing all this by itself, like doing all of the stages of the attacks,β said Guy Waizel, a tech evangelist at Cato Networks and one of the authors behind the research.
Critically, the most successful scenarios happened when the model was given appropriate operational context from the technical harness developed by Cato Networks.
βIt does support that itβs not just about the frontier model,β said Waizel. βWe found that [our harness] really helps the reasoningβ of the LLM.

The agent was given some β but not abundant β resources to complete its tasks, including an external Kali Linux attack host, the simulated targetβs public IP address and a set of low-level domain credentials acquired through phishing.
It was not provided with any other details, and had to probe further for key information, such as further knowledge of the server type (Microsoft Exchange), the targetβs operating system, version, build number, internal network topology, access to higher privilege accounts and other critical assets, nor was agent given any predetermined attack paths.
The Cato Networks research uses OpenAI models, but only as an example. Waizel said he believes other models would likely achieve similar results. In any event, if current trends hold, the kind of capabilities provided by LLMs like GPT 5.5 are likely to be open-source within a year.
Cato Networks is far from alone. Most enterprises have their own AI harnesses, andΒ executives tell CyberScoop they are playing an increasing role in more effectively steering the frontier model workflows.
While AI tools can struggle to duplicate human workflows in other areas, LLMs have long shown potential in cybersecurity and coding, improving greatly over the past few years. The Trump administration has set up a new federal clearinghouse for exchanging information between the public and private sectors on AI-discovered vulnerabilities, while European groups are setting up their own organizations to coordinate globally on AI cyber threats.
Eric Doerr, chief product officer at Tenable, told CyberScoop a harness used in the company called βHexaβΒ offers a defensive advantage:Β it can work withΒ different commercial LLMs while delivering consistentΒ results.
βOne of the first things we do when we get a [new] model is say βWell, letβs run it through Hexa and see what we learn,ββ said Doerr. βWe have a whole bunch of benchmarks. Is it the same, is it better? Where is it better? Where is it worse?β
Hexa is meant to ensure that whichever model or models become dominant, Tenable will be able to integrate it into their tech stack and protect their most sensitive assets from unintended behaviors. That frees up the LLM to do what it does best: find vulnerable code and establish attacker pathways for exploiting them.
βFor years, it has been true that there are way more potential issues that a company has to deal with: code vulnerabilities, things that are unpatched, misconfigurations,β said Doerr. βThereβs way more than you can actually remediate, and you really need to understand the difference between whatβs a theoretical problem and a real problem.β
Dan Rapp, chief AI and data officer at Proofpoint, said their harness, βSatori,β has become a critical tool for keeping their agentic AI on track while giving humans the ability to step in when things go awry.
βI think what youβre seeing in the foundation of frontier models is you have raw intelligence, raw reasoning power, but to get these systems to perform the way you want to, both context engineering β the content provided ensuring that its accurate and relevant β and the harness engineering are essential to actually get the systems to perform well,β Rapp told CyberScoop.
That was a common theme in interviews with companies. While frontier models come and go, or are overtaken by international competitors, there will always be the need for the model to operate with data and context that often only the organization can provide.Β Β
It suggests that while policymakers and cybersecurity experts have focused on the spread of newer and more powerful frontier models, industry β and likely soon the cybercriminal underground β has quickly developed the kind of technical infrastructure that is becoming far more important to AI cyber defensive and offensive tasks.
βWeβve had to bootstrap quite a few of these systems from first principles, and what it always boils down to is how effective you are with the tool callingβ¦ bringing in data, enriching the context,β said John Hopper, vice president of product engineering at SpecterOps.
The post Forget the model. When it comes to cybersecurity, itβs all about the harness appeared first on CyberScoop.
Read more of this story at Slashdot.
Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access.
The post 15-Year-Old Linux Vulnerability βGhostLockβ Earns Researchers $92k From Google appeared first on SecurityWeek.
The 16-year-old Januscape flaw affects Linux's KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host.
The post Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems appeared first on SecurityWeek.
Organizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit.
The post Proof-of-Concept Exploit Released for Linux βBad Epollβ Root Access Vulnerability appeared first on SecurityWeek.
Read more of this story at Slashdot.
A variant of DirtyFrag, the flaw allows unprivileged local users to manipulate the Linux page cache and gain root privileges.
The post βDirtyCloneβ Linux Kernel Vulnerability Leads to Root Access appeared first on SecurityWeek.
Read more of this story at Slashdot.
Read more of this story at Slashdot.