[
  {
    "date": "2026-09-07",
    "title": "zkSecurity: the year finding and exploiting bugs became cheap",
    "url": "https://blog.zksecurity.xyz/posts/the-year-finding-bugs-became-cheap/",
    "summary": "Argues for layered continuous security; counts crypto hacks rising from 16 in January to 50 in August 2026."
  },
  {
    "date": "2026-08-22",
    "title": "AI Grinding for cryptanalysis paper",
    "url": "https://arxiv.org/abs/2608.21986",
    "summary": "Agent-generated hypotheses tested by exact computation; claims reproducible failures in eight published constructions."
  },
  {
    "date": "2026-08-21",
    "title": "Claude Security available to enterprises on Claude Mythos 5",
    "url": "https://claude.com/blog/bringing-claude-mythos-5-to-more-defenders",
    "summary": "Billed as standard token usage."
  },
  {
    "date": "2026-08-20",
    "title": "Ethereum Foundation, Yukon and zkSecurity launch better.codes",
    "url": "https://blog.ethereum.org/2026/08/20/better-codes-challenge",
    "summary": "AI agents raise a Lean-checked soundness bound; the kernel judges every submission."
  },
  {
    "date": "2026-08-15",
    "title": "AISLE reports six curl CVEs after Mythos and Codex Security found none",
    "url": "https://aisle.com/blog/aisle-discovered-six-curl-cves-after-openai-and-anthropic-found-zero",
    "summary": "Low-severity issues fixed in curl 8.22.0."
  },
  {
    "date": "2026-08-05",
    "title": "zkSecurity releases zk-skills and circom-auditor",
    "url": "https://blog.zksecurity.xyz/posts/circom-auditor/",
    "summary": "66 of 70 on zkbugs direct mode; 40 of 56 on full codebases."
  },
  {
    "date": "2026-07-24",
    "title": "zkao 2.0: prepaid credits, collaborative agents, triage tooling",
    "url": "https://blog.zksecurity.xyz/posts/zkao-2-0/",
    "summary": "Subscriptions replaced by non-expiring credits with per-scan caps."
  },
  {
    "date": "2026-07-22",
    "title": "zkao finds four zero-days in Bron Labs bron-crypto",
    "url": "https://blog.zksecurity.xyz/posts/bron-bugs/",
    "summary": "Dual-agent auditor and validator pipeline; all four fixed via bounty."
  },
  {
    "date": "2026-07-21",
    "title": "Google releases Gemini 3.5 Flash Cyber and CodeMender preview",
    "url": "https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/",
    "summary": "55 confirmed V8 issues; access gated."
  },
  {
    "date": "2026-07-17",
    "title": "zkao finds critical OpenVM soundness bug CVE-2026-46669",
    "url": "https://blog.zksecurity.xyz/posts/openvm-bugs/",
    "summary": "Missing subfield check in the pairing guest library let a prover forge pairing equalities; fixed in OpenVM 1.6.0."
  },
  {
    "date": "2026-07-07",
    "title": "zkao and zkSecurity report seven bugs in Cloudflare CIRCL",
    "url": "https://blog.zksecurity.xyz/posts/circl-bugs/",
    "summary": "Six bounties awarded; severities mis-rated by the AI in both directions."
  },
  {
    "date": "2026-06-15",
    "title": "OpenSSL patches high-severity PKCS#7 use-after-free found with AI",
    "url": "https://www.securityweek.com/openssl-patches-high-severity-vulnerability-found-with-ai/",
    "summary": "CVE-2026-45447, alongside about six flaws credited to an Anthropic researcher."
  },
  {
    "date": "2026-05-22",
    "title": "Anthropic publishes Project Glasswing initial update",
    "url": "https://www.anthropic.com/research/glasswing-initial-update",
    "summary": "More than 10,000 high or critical findings, 530 disclosed, including wolfSSL CVE-2026-5194."
  },
  {
    "date": "2026-04-29",
    "title": "Linux 'Copy Fail' CVE-2026-31431 in the AF_ALG crypto interface",
    "url": "https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/",
    "summary": "Deterministic root exploit found in about an hour by an AI-assisted scan."
  },
  {
    "date": "2026-04-29",
    "title": "Nethermind publishes AuditAgent results on EVMbench",
    "url": "https://www.nethermind.io/blog/auditagent-on-evmbench-what-the-data-shows",
    "summary": "67 percent post-validation recall versus 47 percent for Claude Opus 4.6."
  },
  {
    "date": "2026-03-31",
    "title": "Trail of Bits describes its AI-native practice",
    "url": "https://blog.trailofbits.com/2026/03/31/how-we-made-trail-of-bits-ai-native-so-far/",
    "summary": "About 20 percent of reported bugs first surfaced by AI, all human-validated."
  },
  {
    "date": "2026-03-06",
    "title": "OpenAI releases Codex Security research preview",
    "url": "https://openai.com/index/codex-security-now-in-research-preview/",
    "summary": "1.2 million commits and 14 CVEs in thirty days."
  },
  {
    "date": "2026-03-02",
    "title": "OpenZeppelin audits EVMbench",
    "url": "https://www.openzeppelin.com/news/openai-evmbench-audit",
    "summary": "Invalid high-severity items and contamination risk identified."
  },
  {
    "date": "2026-02-20",
    "title": "Anthropic launches Claude Code Security research preview",
    "url": "https://anthropic.com/news/claude-code-security",
    "summary": "Claims 500 vulnerabilities found in production open source."
  },
  {
    "date": "2026-02-18",
    "title": "OpenAI and Paradigm release EVMbench",
    "url": "https://openai.com/index/introducing-evmbench/",
    "summary": "117 vulnerabilities from 40 audits."
  },
  {
    "date": "2026-02-07",
    "title": "zkSecurity launches zkao",
    "url": "https://blog.zksecurity.xyz/posts/zkao-launch/",
    "summary": "AI bug detection for cryptography code, Circom first."
  },
  {
    "date": "2026-01-31",
    "title": "curl ends its bug bounty over AI-generated reports",
    "url": "https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/",
    "summary": "Confirmed-report rates had fallen below five percent."
  },
  {
    "date": "2026-01-27",
    "title": "AISLE credited with 12 of 12 OpenSSL CVEs",
    "url": "https://aisle.com/blog/aisle-discovered-12-out-of-12-openssl-vulnerabilities",
    "summary": "Three bugs dated to 1998 to 2000."
  },
  {
    "date": "2025-10-01",
    "title": "Nethermind publishes AuditAgent recall on 29 real audits",
    "url": "https://www.nethermind.io/blog/how-nethermind-security-uses-auditagent-alongside-manual-audits",
    "summary": "30 percent average recall; 42 percent of criticals."
  },
  {
    "date": "2025-09-25",
    "title": "Zellic introduces V12",
    "url": "https://www.zellic.io/blog/introducing-v12/",
    "summary": "LLM plus static analysis for Solidity."
  },
  {
    "date": "2025-08-08",
    "title": "DARPA AIxCC final results",
    "url": "https://www.darpa.mil/news/2025/aixcc-results",
    "summary": "54 million lines scanned, 18 real zero-days, 43 of 54 synthetic bugs patched; Team Atlanta, Trail of Bits, Theori on the podium."
  },
  {
    "date": "2025-06-18",
    "title": "Zero Knowledge Podcast: AI and ZK auditing with David Wong",
    "url": "https://zeroknowledge.substack.com/p/ai-and-zk-auditing-with-with-david",
    "summary": "Early public discussion of zkSecurity's AI auditing approach."
  }
]