<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>YFarmX AI-Found Vulnerability Register</title><description>New entries on the YFarmX AI-Found Vulnerability Register: every vulnerability credited to an AI finder, with the evidence tier, the credit as recorded and the source on every entry.</description><link>https://yfarmx.com/</link><language>en-GB</language><item><title>Google OSS-Fuzz-Gen reports 30 new bugs found by automatically generated fuzz targets</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0060/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0060/</guid><description>The README table lists 23 named-project rows and seven undisclosed rows, two of them pending maintainer triage, totalling the 30 it claims. One entry carries a CVE, CVE-2024-9143, which is its own row here.</description><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><category>Google OSS-Fuzz-Gen</category><category>aggregate</category><category>CONFIRMED</category></item><item><title>Anthropic reports an autonomous exploit workflow yielding more than a dozen possible zero-days in a month</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0066/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0066/</guid><description>Anthropic&apos;s September 2026 threat report describes an exploit foundry that ran firmware decryption through a decompiler tool server to tested exploit code, with findings the actor kept. &quot;Possible&quot; is the report&apos;s own word.</description><pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate><category>GTG-10007 exploit workflow (threat actor)</category><category>aggregate</category><category>CONFIRMED</category></item><item><title>Chrome V8 out-of-bounds write exploited in the wild, found by a human researcher and paid $2,500 (the control row)</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0047/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0047/</guid><description>Fixed in Chrome 153.0.8010.36 on 8 September 2026 and exploited in the wild by a third party. The row sits in the register as a control: headlines conflated it with an AI-derived exploit chain built on 3 September, and the release note credits a person, with a $2,500 reward.</description><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate><category>Jihyeon Jeong (human researcher)</category><category>cna-advisory</category><category>CONFIRMED</category></item><item><title>WebKitGTK memory corruption in OpenTypeVerticalData, found by Google Big Sleep</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0018/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0018/</guid><description>A memory corruption in WebKitGTK from 1.10.0, assigned by Red Hat on 31 August 2026 with a Big Sleep acknowledgement, the newest Big Sleep record in the register.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>Google Big Sleep</category><category>credits-array</category><category>CONFIRMED</category></item><item><title>Anthropic attributes 500 or more high-severity vulnerabilities that survived decades of scrutiny to Claude Opus</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0068/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0068/</guid><description>A separate figure from the Glasswing count, filed under Claude Opus rather than Mythos, with no identifier list.</description><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate><category>Claude Opus (Anthropic)</category><category>aggregate</category><category>CONFIRMED</category></item><item><title>Anthropic says Project Glasswing partners found more than 10,000 high- or critical-severity flaws</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0067/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0067/</guid><description>On 2 June 2026 Anthropic said it was extending Glasswing to about 150 more organisations and that partners had by then found more than 10,000 high- or critical-severity flaws. No identifier list accompanies the figure.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>Claude Mythos Preview and Mythos 5 (Project Glasswing)</category><category>aggregate</category><category>CONFIRMED</category></item><item><title>depthfirst reports 21 FFmpeg zero-days from a $1,000 scan of 1.5 million lines</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0061/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0061/</guid><description>Opened on 19 September 2026: the page dates itself 2 June 2026, names nine CVE identifiers and twelve DFVULN identifiers, and says the twelve are fixed with no CVE assigned yet. The most severe, DFVULN-127, is described as a heap buffer overflow in the AV1 RTP depacketizer reachable from one 183-byte packet.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>depthfirst autonomous security agent</category><category>aggregate</category><category>CONFIRMED</category></item><item><title>FFmpeg heap overflow in the DASH demuxer, claimed by depthfirst under an identifier the CVE list does not yet serve</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0056/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0056/</guid><description>One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine &quot;have already been assigned CVEs&quot;; the CVE Program&apos;s own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>depthfirst autonomous security agent</category><category>claimed</category><category>UNVERIFIED</category></item><item><title>FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0055/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0055/</guid><description>One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine &quot;have already been assigned CVEs&quot;; the CVE Program&apos;s own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>depthfirst autonomous security agent</category><category>claimed</category><category>UNVERIFIED</category></item><item><title>FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0054/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0054/</guid><description>One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine &quot;have already been assigned CVEs&quot;; the CVE Program&apos;s own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>depthfirst autonomous security agent</category><category>claimed</category><category>UNVERIFIED</category></item><item><title>FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0053/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0053/</guid><description>One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine &quot;have already been assigned CVEs&quot;; the CVE Program&apos;s own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>depthfirst autonomous security agent</category><category>claimed</category><category>UNVERIFIED</category></item><item><title>FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0052/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0052/</guid><description>One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine &quot;have already been assigned CVEs&quot;; the CVE Program&apos;s own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>depthfirst autonomous security agent</category><category>claimed</category><category>UNVERIFIED</category></item><item><title>FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0051/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0051/</guid><description>One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine &quot;have already been assigned CVEs&quot;; the CVE Program&apos;s own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>depthfirst autonomous security agent</category><category>claimed</category><category>UNVERIFIED</category></item><item><title>FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0050/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0050/</guid><description>One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine &quot;have already been assigned CVEs&quot;; the CVE Program&apos;s own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>depthfirst autonomous security agent</category><category>claimed</category><category>UNVERIFIED</category></item><item><title>FFmpeg integer overflow in the swscale, claimed by depthfirst under an identifier the CVE list does not yet serve</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0049/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0049/</guid><description>One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine &quot;have already been assigned CVEs&quot;; the CVE Program&apos;s own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>depthfirst autonomous security agent</category><category>claimed</category><category>UNVERIFIED</category></item><item><title>FFmpeg heap overflow in the MPEG-TS demuxer, claimed by depthfirst under an identifier the CVE list does not yet serve</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0048/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0048/</guid><description>One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine &quot;have already been assigned CVEs&quot;; the CVE Program&apos;s own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>depthfirst autonomous security agent</category><category>claimed</category><category>UNVERIFIED</category></item><item><title>Google CodeMender upstreamed 72 security fixes in its first six months</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0069/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0069/</guid><description>CodeMender fixes rather than finds: 72 security patches upstreamed over six months, each human-reviewed, with the model inside the harness moving from Gemini Deep Think to Gemini 3.5 Flash Cyber and then 3.8 Flash Cyber.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><category>Google CodeMender</category><category>aggregate</category><category>SINGLE</category></item><item><title>Gogs unauthenticated file upload, disclosed by OpenAI Security Research</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0030/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0030/</guid><description>An unauthenticated file upload in Gogs, advisory published 17 February 2026 and CVE record 19 February, whose disclosure header dates the discovery to 5 August 2025, three months before OpenAI announced Aardvark.</description><pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate><category>OpenAI Aardvark</category><category>cna-advisory</category><category>CONFIRMED</category></item><item><title>Gogs two-factor bypass via recovery code, disclosed by OpenAI Security Research</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0029/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0029/</guid><description>A two-factor bypass in Gogs published 6 February 2026 with GitHub as CNA, whose advisory text names OpenAI Security Research as the discloser.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate><category>OpenAI Aardvark</category><category>cna-advisory</category><category>CONFIRMED</category></item><item><title>AISLE claims more than 225 CVEs across OpenSSL, the Linux kernel, curl, Apache, Mozilla, Redis and Elastic</title><link>https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0062/</link><guid isPermaLink="true">https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0062/</guid><description>AISLE says it holds all twelve CVEs in the OpenSSL release of 27 January 2026, credit on 13 of 14 OpenSSL CVEs assigned in 2025, three of the six CVEs fixed in curl 8.18.0, and more than 225 CVEs in total. That last figure would make it the largest contributor here by an order of magnitude and rests on the company&apos;s own pages.</description><pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate><category>AISLE</category><category>aggregate</category><category>SINGLE</category></item></channel></rss>