#VulnCheck
Anthropic-linked CVEs pile up, attackers mostly shrug
Anthropic-linked CVEs pile up, attackers mostly shrug
Of 225 flaws found by Glasswing and tracked by VulnCheck researcher, just one has confirmed exploitation in the wild
www.theregister.com
September 21, 2026 at 10:37 PM
VulnCheck has extracted and made a list of all the CVEs mentioned in a recent leak from the internal Matrix chat server of the BlackBasta ransomware group.

The list includes 62 vulnerabilities.

VulnCheck says the group focuses on CVEs with already public exploits

vulncheck.com/blog/black-b...
February 24, 2025 at 10:32 PM
"Tausende Zero-Days." Patrick Garrity (VulnCheck) hat nachgezählt: Öffentlich verifizierbare CVEs mit Anthropic-Zuschreibung? Niedriger zweistelliger Bereich. 99% der angeblichen Funde sind laut Anthropic "noch nicht gepatcht" — also nicht prüfbar.
May 14, 2026 at 12:53 PM
At least 60 known threat actors exploited vulnerabilities from CISA's list of most exploited bugs last year.

According to security firm VulnCheck, North Korean group Silent Chollima was the most active, targeting 9 out of 15 CVEs from CISA's list.

vulncheck.com/blog/cisa-to...
November 23, 2024 at 9:28 PM
VulnCheck has noted a common trend this year, with new CVEs exploding for some vendors, a clear sign of more vulnerabilities being discovered with the help of AI tools

www.vulncheck.com/blog/ai-assi...
May 17, 2026 at 11:57 AM
"Of 1,061 vulnerabilities attributed to AI-assisted discovery, only 14, or 1.3%, have been confirmed as exploited in the wild..." www.vulncheck.com/blog/state-o...
VulnCheck State of Exploitation 1H-2026 | Blog | VulnCheck
Key Trends and Findings from Known Exploited Vulnerabilities, AI discovered vulnerabilities, and AI targeted technologies from the first half of 2026
www.vulncheck.com
July 28, 2026 at 7:00 PM
そらそうやろ。
今更何言うてんねん。

中国製ルーター20機種にバックドア、外部から完全制御のおそれ(CNET Japan) - Yahoo!ニュース
news.yahoo.co.jp/articles/519...
中国製ルーター20機種にバックドア、外部から完全制御のおそれ(CNET Japan) - Yahoo!ニュース
中国企業Zbtlink製のルーターがバックドアを組み込んだ状態で出荷されていることが、サイバーセキュリティ企業VulnCheckの新たな報告で明らかになった。  VulnCheckはZbtlin
news.yahoo.co.jp
August 6, 2026 at 4:09 AM
Researchers discover additional backdoors in Chinese-made Zbtlink routers reut.rs/4xWSb1w
Researchers discover additional backdoors in Chinese-made Zbtlink routers
More than a dozen models of Chinese-made Zbtlink routers ‌ship with at least two backdoors that could allow for invasive remote access akin to “surveillance,” according to new findings from cybersecurity firm VulnCheck.
reut.rs
August 27, 2026 at 11:05 AM
“The CVE Program is critical, and it’s in everyone’s interest that it succeed," says Patrick Garrity, a security researcher at VulnCheck. “Nearly every organization and every security tool is dependent on this information, and it’s not just the US. It’s consumed globally."
‘Stupid and Dangerous’: CISA Funding Chaos Threatens Essential Cybersecurity Program
The CVE Program is the primary way software vulnerabilities are tracked. Its long-term future remains in limbo even after a last-minute renewal of the US government contract that funds it.
www.wired.com
April 16, 2025 at 8:20 PM
Good stuff from VulnCheck!
January 11, 2024 at 3:44 PM
Hey, security research friends! You know how vulnerability disclosure coordination is the most painful part of vuln research? Good news: VulnCheck will do it for you! You get credit, we handle the CVEs + vendor discussions.

Report vulnerabilities for disclosure here: vulncheck.com/advisories/r...
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
vulncheck.com
September 17, 2025 at 10:40 PM
VulnCheck reported that in Q1 2025, 159 vulnerabilities were actively exploited, with attackers leveraging nearly a third within a day of disclosure, highlighting urgent needs for rapid defense against emerging threats. #CyberSecurity #VulnCheck
cyberscoop.com/vulncheck-kn...
VulnCheck spotted 159 actively exploited vulnerabilities in first few months of 2025
The vulnerability threat intelligence firm’s research reinforces a slew of recent reports warning about increased exploits in 2024.
cyberscoop.com
April 25, 2025 at 1:19 AM
🤖 Anthropic-linked CVEs pile up, attackers mostly shrug

Of 225 flaws found by Glasswing and tracked by VulnCheck researcher, just one has confirmed exploitation in the wild

https://tinyurl.com/2c3zepnc #AINews #MachineLearning #CrustyTLDR
September 22, 2026 at 2:02 AM
go-exploit Goes Scanless
VulnCheck go-exploit Goes Scanless - Blog - VulnCheck
Demonstrating the new scanless feature in the go-exploit exploit framework.
vulncheck.com
July 25, 2024 at 6:30 PM
VulnCheck finds not one, but two new backdoor mechanisms in ZBT routers.

They found a first earlier this month.

Researchers believe its "domestic Chinese surveillance technology" for the Chinese market

www.vulncheck.com/blog/zbt-dar...
Chinese Implants in the Supply Chain | Blog | VulnCheck
In our previous blog, ENDLESSDOORS Is Phoning Home. Pick up, we detailed a phone-home implant vulnerable to man-in-the-middle attacks embedded in ZBT routers. In this blog, we trace the ZBT supply cha...
www.vulncheck.com
August 27, 2026 at 3:34 PM
Excited that our collaboration with
VulnCheck (vulncheck.com) continues to grow as we welcome them as a new Shadowserver Alliance Partner -Silver tier!

We look forward to enhancing our joint efforts to help network defenders globally with vulnerability management.
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
vulncheck.com
December 1, 2025 at 3:20 PM
中国製無線ルーターに「バックドア」 世界10万台設置
www.nikkei.com/article/DGXZQO...

アメリカのセキュリティー企業バルンチェック(VulnCheck)が調査結果を公表。

無線ルーターの制御ソフトに、外部からの遠隔操作を可能にする仕組みがあることが判明しました。

ルーターの起動時に自動で動作し、約35秒ごとに特定のIPアドレスや中国のドメインと通信するといいます。

#ニュース
米調査会社、中国製無線ルーターに「バックドア」 世界10万台設置 - 日本経済新聞
【ニューヨーク=内山瑞貴】米セキュリティー企業が5日、中国製の無線ルーターの制御ソフトに、外部から遠隔操作を可能にする「バックドア」が組み込まれているとする調査結果を公表した。製造元は指摘を受け急きょ販売を停止した。中国製通信機器を巡る安全保障上の懸念が改めて浮き彫りになった。調査したのは米東部マサチューセッツ州にあるサイバーセキュリティー企業のバルンチェック(VulnCheck)。中国の通信
www.nikkei.com
August 6, 2026 at 10:10 PM
AI-found bugs aren't proving any easier to exploit despite the hype
AI-found bugs aren't proving any easier to exploit despite the hype
VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage
www.theregister.com
July 28, 2026 at 3:29 PM
"five months into Project Glasswing, only 9.8% of the findings have made it to a project maintainer"

https://www.vulncheck.com/blog/anthropic-glasswing-receipts
The Anthropic Glasswing Receipts Are Starting to Trickle In | Blog | VulnCheck
A look into Anthropic Glasswing's latest update to their vulnerability disclosure ledger.
www.vulncheck.com
September 8, 2026 at 3:16 PM
The vulnerability threat intelligence firm’s research reinforces a slew of recent reports warning about increased exploits in 2024. via @mattkapko.com cyberscoop.com/vulncheck-kn...
VulnCheck spotted 159 actively exploited vulnerabilities in first few months of 2025
The vulnerability threat intelligence firm’s research reinforces a slew of recent reports warning about increased exploits in 2024.
cyberscoop.com
April 25, 2025 at 12:34 PM
大手メディアももっとしっかり報道してくれないと困りますな
中国製ルーター20機種にバックドア、外部から完全制御のおそれ
中国企業Zbtlink製のルーターがバックドアを組み込んだ状態で出荷されていることが、サイバーセキュリティ企業VulnCheckの新たな報告で明らかになった。
japan.cnet.com
August 6, 2026 at 3:59 AM