21 zero-days in FFmpeg, an 18-year-old NGINX hole: depthfirst targets the unguarded open-source floor
ccerrato147 · x · 2026-09-19
ccerrato147 points to a pattern: 21 zero-days in FFmpeg, an 18-year-old hole in NGINX, and a TikTok vulnerability traced to an open-source dependency — all in the same unguarded 'floor' nobody is paid to inspect. depthfirst, whose base model is publicly downloadable, is filling that gap.
More from Safety
- AI-assisted exploit development for Apple's XNU kernel shown at security conference — moyix · 2026-09-19
- DeepTeam: Open-source framework for red teaming LLMs locally — tom_doerr · 2026-09-19
- Exclusive: OpenAI's Sam Altman to brief UN Security Council next week — gaganghotra_ · 2026-09-19
- micro1: frontier models controlling real hardware is a pressing AI safety problem — Exp_Mark · 2026-09-19
- Simulated Claude arms spill toxic liquids and use harmful force in micro1 safety tests — Exp_Mark · 2026-09-19
- ICML paper warns against platform agents, calls for user-controlled 'agent advocates' — xuanalogue · 2026-09-19