Common Weakness Enumeration
PulseAugur coverage of Common Weakness Enumeration — every cluster mentioning Common Weakness Enumeration across labs, papers, and developer communities, ranked by signal.
3 day(s) with sentiment data
-
New Benchmark Tests AI Agents' Ability to Locate Software Vulnerabilities
Researchers have introduced the Vulnerability Localization Benchmark (VLoc Bench), a new dataset designed to evaluate the ability of AI agents to identify specific code locations associated with security vulnerabilities…
-
AI code generation security evaluated with new benchmarks and dynamic testing
Two new research papers explore the challenges of generating secure code with AI models. The first paper introduces CodeSecEval, an execution-based benchmark for evaluating secure code generation, and proposes SecAwareC…
-
New framework turns vulnerability history into executable detection rules
Researchers have developed BUGSTONE-E2E, a framework designed to transform historical vulnerability data into executable detection rules. This system mines fixing commits to create reusable rules, which are then process…
-
New framework enables targeted poisoning of AI-generated code
Researchers have developed a new framework called CodePoisonRAG that can inject specific vulnerabilities into code generated by Retrieval-Augmented Code Generation (RACG) systems. This framework works by transforming be…
-
Athena system uses knowledge graphs to identify vulnerable software libraries
Researchers have developed Athena, a novel graph-based system designed to identify libraries affected by software vulnerabilities. Unlike previous methods that treat vulnerability data as isolated text, Athena models th…
-
Anthropic integrates advanced Claude Mythos 5 into Claude Security for enterprise vulnerability scanning
Anthropic has integrated its advanced Claude Mythos 5 model into its Claude Security product, offering enterprise clients enhanced vulnerability scanning capabilities. This new feature allows teams to scan GitHub reposi…
-
New agent detects misinformation in RAG systems
Researchers have developed an "Evaluation Agent" to address the security and reliability gap in Retrieval-Augmented Generation (RAG) systems. This agent acts as middleware to detect misinformation and knowledge poisonin…
-
New CTIFoundry corpus scaffold boosts LLM agent cyber threat intelligence
Researchers have introduced CTIFoundry, a new corpus scaffold designed to enhance the capabilities of LLM agents in cyber threat intelligence (CTI). This system structures CTI data by creating an ontology graph from aut…
-
AI code generation pipeline tackles security vulnerabilities
A new research paper introduces an automated pipeline designed to detect and fix security vulnerabilities in code generated by AI development tools. The pipeline processes code from LLM-generated prompts, uses tools lik…
-
New VICBench benchmark evaluates code vulnerability detection tools · 2 sources tracked
Researchers have introduced VICBench, a new benchmark designed to evaluate code vulnerability detection tools. The benchmark comprises 100 verified vulnerability-inducing commits (VICs) across 88 projects in Python, Jav…
-
New AVE standard addresses AI agent behavioral vulnerability classification
A new open standard called AVE (Agentic Vulnerability Enumeration) has been developed to classify behavioral vulnerabilities in AI agents, addressing a gap left by existing systems like CVE and CWE. These traditional sy…
-
New Classifier Maps CVEs to MITRE ATT&CK Techniques, LLM Labeling Shows No Benefit
Researchers have developed a reproducible pipeline to map Common Vulnerabilities and Exposures (CVEs) to MITRE ATT&CK Enterprise techniques using free-text descriptions. Their custom-trained classifier, built on expert-…
-
New training method boosts AI's Python vulnerability prediction
Researchers have developed a new method for training AI models to predict software vulnerabilities in Python code, specifically focusing on the Common Weakness Enumeration (CWE) taxonomy. They found that directly using …
-
Cisco Foundation AI releases Antares models for code vulnerability localization
Cisco Foundation AI has introduced Antares, a new family of open-weight small language models designed specifically for vulnerability localization in code. The models, Antares-350M and Antares-1B, are available on Huggi…
-
Open-weight LLMs evaluated for autonomous vehicle threat intelligence generation
Researchers have developed a new dataset, CAV-STIXGen, to evaluate open-weight Large Language Models (LLMs) in generating structured threat information for autonomous vehicle vulnerabilities. The study assessed 11 LLMs,…
-
New RoBERTa Framework Tackles Class Imbalance in Cybersecurity Vulnerability Classification
A new research paper proposes a Hierarchy-Aware RoBERTa framework to address class imbalance in cybersecurity vulnerability classification using the Common Weakness Enumeration (CWE) taxonomy. The framework explicitly i…
-
FLARE-AI launches platform for reporting AI vulnerabilities
FLARE-AI has introduced a new platform designed to facilitate the reporting of AI vulnerabilities. This open and shared solution aims to address the growing need for identifying and correcting flaws in AI models. The pl…
-
New SecVecCoder method enhances LLM code generation security
Researchers have developed a new method called SecVecCoder that uses task vectors to improve the security and functionality of code generated by large language models (LLMs). This technique modifies LLM weights to enhan…
-
BERT models compared for CVE-to-CWE mapping, taxonomy structure key
Researchers explored the effectiveness of multi-class versus multi-label BERT models for mapping Common Vulnerabilities and Exposures (CVE) to Common Weakness Enumeration (CWE) categories. Their study, which evaluated B…
-
BERT models compared for CVE-to-CWE mapping in cybersecurity research
A new research paper explores the effectiveness of different BERT models for mapping Common Vulnerabilities and Exposures (CVE) to Common Weakness Enumeration (CWE) categories. The study compares multi-class and multi-l…