All posts tagged: patching

Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

Google’s Chrome browser has always been focused on pushing security updates. A decade ago it was controversial that the browser, the first to add automatic updates, distributed patches every six weeks. Now it’s the norm for critical, widely used software to get security fixes every few weeks, but as AI vulnerability hunting produces a torrent of bugs in any and all software, the quantity and frequency of patches is spiking—and the race to deliver them is on. In a report published Thursday, the Chrome security team says the browser’s two major version releases in June included fixes for 1,072 security bugs—more patches than the team shipped in the prior 23 big releases combined. And though many of these bugs come from researcher submissions, the spike has largely been driven by the Chrome security team’s rapidly evolving internal process for using AI tools in vulnerability discovery, triage, and patch development. “In chrome we’ve been using machine learning—using AI before it was called AI—to help find vulnerabilities in particular and automate security fuzz testing work since at …

Claude Mythos exposed a hard truth: Your enterprise patching process is way too slow

Claude Mythos exposed a hard truth: Your enterprise patching process is way too slow

In 2024, researchers from the University of Illinois found that GPT-4, when provided with a common vulnerabilities and exposures (CVE) description, could autonomously exploit 87% of a curated 15-vulnerability one-day dataset. Without the description, it could only exploit 7%. This provided a “margin of safety” for the industry because while AI could exploit known vulnerabilities, it could not discover them. However, on April 7, Anthropic announced that Claude Mythos Preview had closed that margin, with the model autonomously discovering thousands of zero-day vulnerabilities across major operating systems and browsers. Separately, Mythos scored 83.1% on the CyberGym vulnerability reproduction benchmark. In one campaign targeting OpenBSD across 1,000 scaffold runs, the total compute cost was less than $20,000. Exploitation timelines are collapsing. Langflow’s CVE-2026-33017 (CVSS 9.8) was exploited 20 hours after disclosure with no public proof-of-concept. Marimo’s CVE-2026-39987 (CVSS 9.3) was hit in 9 hours and 41 minutes. The defensive infrastructure most organizations rely on wasn’t designed for this. Rapid7’s 2026 threat landscape report states that the median time from CVE publication to CISA’s known exploited vulnerabilities …

Sewing Bee winner Annie Phillips’ guide to upcycling clothes: from patching to quilting

Sewing Bee winner Annie Phillips’ guide to upcycling clothes: from patching to quilting

If you’re a Great British Sewing Bee fan, you might remember my face. I’m Annie Phillips. I won the 2022 series of the show and now I sew for a living. I divide my time between running my own fashion house (Made by Annie) and leading upcycling workshops to breathe new life back into your wardrobe. I’ve even written a book on the subject called Upcycle: A Modern Maker’s Guide to Sewing and Mending a Preloved Wardrobe. Some of the people who sign up for my classes have never used a sewing machine before, while others are more experienced, but most are coming for the same reason. They’ve fallen out of love with their wardrobe, but they can’t bring themselves to buy new clothes when their old ones still have so much wear. If that sounds like you, then you should try your hand at upcycling. It’s just another word for the “make do and mend” ethos that has inspired generations of sewers. Here are my top tips for first-timers. You can see all the …