Research topicVulnerabilities & CVEs
Specific, disclosed security flaws in AI systems and the tools around them.
Korpalis selects material that helps builders and business teams understand what changed, why it matters and what to check next. Every entry below includes an original explanation and a direct link to its publisher.
Vulnerabilities & CVEsAdvanced
Researchers documented dozens of attack methods against passkey systems that do not require breaking the underlying FIDO2 cryptography but instead exploit trust boundaries in enrollment, recovery, and credential handling, showing that the cryptographic strength alone does not guarantee authentication security.
Vulnerabilities & CVEsIntermediate
A long-dormant database replication vulnerability can be chained to achieve permanent administrative compromise and persistent backdoor access to PostgreSQL systems.
Vulnerabilities & CVEsIntermediate
Google released a Chrome update fixing an actively exploited zero-day in the V8 JavaScript engine along with 11 other vulnerabilities. The V8 flaw poses immediate risk to browser users and developers using V8-based tools.
Vulnerabilities & CVEsBeginner
A SQL injection vulnerability in a widely-deployed WordPress migration plugin could allow attackers to execute arbitrary code on millions of affected websites. The high severity and unauthenticated attack vector make patching critical for site operators.
Vulnerabilities & CVEsBeginner
A critical SQL injection vulnerability in a widely-used WordPress backup plugin allows unauthenticated attackers to execute arbitrary code and fully compromise affected websites. Administrators should update immediately.
Vulnerabilities & CVEsIntermediate
Analysis of a ransomware campaign targeting thousands of WordPress sites through ClickFix social engineering, revealing the complete infection chain from initial prompt to payload delivery and the infrastructure supporting the operation.
Vulnerabilities & CVEsIntermediate
This empirical study examines whether iterative LLM-based repair of Infrastructure-as-Code inadvertently introduces new security regressions while fixing existing issues. The findings challenge commonly reported cumulative improvement metrics by analyzing per-iteration security outcomes, revealing potential risks in automated remediation workflows.
Vulnerabilities & CVEsAdvanced
This work introduces a dual-signal watermarking scheme for LLM outputs that simultaneously proves provenance and detects tampering, addressing a gap where existing robust watermarks paradoxically enable attackers to modify content while maintaining false attribution. The approach uses complementary signals within the same watermarking mechanism to provide both protections.