#DepthFirst
An employee from DepthFirst, a cybersecurity start-up, was able to remotely access the camera and photo roll on a phone browsing TikTok with a free AI model.

DepthFirst disclosed the vulnerability to TikTok, which confirmed it and fixed the problem, messages show. https://wapo.st/4AqveGa
September 19, 2026 at 10:00 AM
An employee from DepthFirst, a cybersecurity start-up, was able to remotely access the camera and photo roll on a phone browsing TikTok with a free AI model.

DepthFirst disclosed the vulnerability to TikTok, which confirmed it and fixed the problem, messages show. wapo.st/4ivBTYZ
They hacked a TikTok user’s camera, with help from free AI
Chinese AI models given away free have potent cybersecurity skills, widening access to high-level hacking knowledge that can be used for good or ill.
wapo.st
September 19, 2026 at 11:22 AM
𝗩𝗜𝗕𝗘 𝗖𝗛𝗘𝗖𝗞: Disquieting

DepthFirst employee remotely accessed TikTok users' phone cameras and photo rolls via an AI model; TikTok confirmed and fixed the vulnerability.
September 19, 2026 at 10:00 AM
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.

The…
#hackernews #news
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst
thehackernews.com
September 24, 2026 at 8:16 AM
Don't Trust AI.

An employee from DepthFirst, a cybersecurity start-up, was able to remotely access the camera and photo roll on a phone browsing TikTok with a free AI model.

DepthFirst disclosed the vulnerability to TikTok, which confirmed it and fixed the problem, messages show. wapo.st/3UZ8Xim
They hacked a TikTok user’s camera, with help from free AI
Chinese AI models given away free have potent cybersecurity skills, widening access to high-level hacking knowledge that can be used for good or ill.
wapo.st
September 19, 2026 at 2:53 PM
How an open-weight AI model hacked TikTok: the DepthFirst Labs camera and microphone exploit

Researchers at DepthFirst Labs used an AI agent to exploit TikTok code, demonstrating a zero-click RCE chain that could…

https://thecybersecguru.com/news/tiktok-ai-hack-depthfirst-labs-zero-click-rce/
September 19, 2026 at 6:01 PM
Critical vulnerability alert! 🚨 1-click RCE in Moltbot could compromise your data & keys. Patch NOW! Read more: [Link to depthfirst article] #security #vulnerability #rce #moltbot #cybersecurity
February 1, 2026 at 9:44 PM
The company used an AI-native platform to help companies fight threats.
AI security firm, depthfirst, announces $40 million series A | TechCrunch
The company used an AI-native platform to help companies fight threats.
techcrunch.com
January 14, 2026 at 3:55 PM
I'm hesitant to link the AI influencer video I've just seen but one of the very funny things about AI "vulnerability research" is that essentially AI weirdos are learning from the ground up that the powerful models aren't as good at VR as an effective VR methodology.

depthfirst.com/research/21-...
21 Zero-Days in FFmpeg | depthfirst
depthfirst's production autonomous security agent discovered 21 zero-day vulnerabilities in FFmpeg, after intensive security analysis by Google and Anthropic. Moving beyond theoretical analysis, our a...
depthfirst.com
June 17, 2026 at 6:46 AM
🚨 NEW 🚨 A new Mythos-competing AI model has found major vulnerabilities affecting some of the most widely-deployed code on the web.

One is in NGINX, software that runs the majority of the most visited sites on the web. It's a remote code execution flaw from 2008...

www.forbes.com/sites/thomas...
This Startup’s AI Found Critical Vulnerabilities That Anthropic’s Mythos Missed
Startup Depthfirst claims its AI found some major flaws in tools that help run much of the internet, all for a tenth of the cost of Anthropic’s comparable model Mythos.
www.forbes.com
May 12, 2026 at 2:11 PM
I am a fan of #ShortestPath problems :) so many other hard problems can be reduced to #PathFinding problems.

Approaching them from a #ComputerScience perspective the question of:

#DepthFirst or #BreadthFirst is eternal :)
October 27, 2025 at 10:38 PM
Public exploit code for CVE-2026-80521 escapes Ubuntu 26.04 containers to root on the host. Fixed upstream in August, but Ubuntu still lists 26.04 as vulnerable.

Again, Ubuntu is behind on security.

depthfirst.com/research/con...

#Linux #Ubuntu #Security
Containers Are No Longer a Security Boundary | depthfirst
As AI accelerates kernel vulnerability discovery and exploitation, the barrier to escaping containers by attacking kernel has fallen so significantly that we must assume attackers can do so at will.
depthfirst.com
September 23, 2026 at 3:02 PM
depthfirst raised $120M in under 90 days to point AI agents at the vulnerabilities attackers now find with AI too.

https://yespress.io/depthfirst?utm_source=bluesky&utm_medium=social via Yespress
depthfirst - The AI Lab Teaching Machines to Secure Software
An AI-native security lab that reads your code the way an attacker would - then hands developers a fix. $120M raised in under 90 days.
yespress.io
August 18, 2026 at 9:47 AM
This startup's AI model found security flaws Anthropic's Mythos missed--and it runs at a tenth of the cost, reports by colleague @thomasbrewster.bsky.social

www.forbes.com/sites/thomas...
This Startup’s AI Found Critical Vulnerabilities That Anthropic’s Mythos Missed
Startup Depthfirst claims its AI found some major flaws in tools that help run much of the internet, all for a tenth of the cost of Anthropic’s comparable model Mythos.
www.forbes.com
May 12, 2026 at 10:11 PM
dfs-large1: fine-tuned GLM-5.2 for cybersec

huge congrats to depthfirst on finetuning this and getting good enough perf to hit the pareto-optimal frontier

-- looks like the better your fine-tuning results, the higher you can price. can't do that without open models!
depthfirst.com/research/dfs...
August 3, 2026 at 1:08 PM
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain

Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exp…
#hackernews #news
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain
Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in Oj, a Ruby JSON parser with a native C implementation, into full command execution inside […]
securityaffairs.com
July 28, 2026 at 5:42 AM
NGINX Rift: Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability | depthfirst #devopsish depthfirst.com/resea...
May 18, 2026 at 3:09 PM