Close Menu
    What's Hot

    YouTuber and Wife Ended Pregnancy After Down Syndrome Diagnosis. They Got Death Threats.

    Man dies in Western Australia after shark attack | News

    Could you be the FT’s new stock picking champion?

    Facebook X (Twitter) Instagram
    Trending
    • YouTuber and Wife Ended Pregnancy After Down Syndrome Diagnosis. They Got Death Threats.
    • Man dies in Western Australia after shark attack | News
    • Could you be the FT’s new stock picking champion?
    • Transfer rumors, news: Bayern’s Olise is Real Madrid target for Perez
    • Vaibhav Sooryavanshi: India’s 15-year-old cricket star named in T20 squads to play England and Ireland | Cricket News
    • Congress still can’t decide what to do about warrantless surveillance
    • AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
    • AI is rewriting the logic of management
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

    adminBy adminJune 6, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJun 06, 2026Vulnerability / Endpoint Security

    AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

    Two things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all of them found by an autonomous AI agent.

    The same week, Google shipped Chrome 149 with patches for 429 security bugs, the most ever in a single release.

    Only the FFmpeg bugs were found by AI. Chrome’s record landed after Google overhauled its bounty program to cope with a flood of AI-generated reports. The mechanisms differ, but the pressure is the same: AI is putting more vulnerabilities in front of the people who have to deal with them, and faster than before.

    The FFmpeg findings come from depthfirst, whose autonomous security agent scanned the project’s roughly 1.5 million lines of C and produced 21 confirmed zero-days, each with a reproducible proof-of-concept input.

    The company puts the cost of the run at around $1,000. Several of the bugs had been latent for 15 to 20 years; one stack overflow in the service-description-table code dates to 2003 and sat untouched for 23 years.

    Cybersecurity

    Most are heap or stack overflows in parsers and demuxers, spanning components from the TS demuxer to the VP9 decoder. depthfirst says some already carry CVE identifiers; its writeup lists nine, CVE-2026-39210 through CVE-2026-39218, and notes the rest are fixed but not yet numbered. It also published a PoC.

    In separate news, Chrome 149 fixes 429 vulnerabilities, a record for a single release. Over 100 are critical or high severity, mostly use-after-free and insufficient input validation.

    The worst, CVE-2026-10881 (CVSS 9.6), is an out-of-bounds read and write in the ANGLE graphics engine that lets a crafted page escape the sandbox and run code on the host. Google paid $97,000 for it.

    The highest-severity bugs were mostly internal finds: of roughly 90 high-severity bugs, only 10 came from outside researchers, and 19 of the 22 critical ones were Google’s own. The AI connection is more about volume than authorship.

    Google hasn’t tied the 429 to AI; the on-record signal is the bounty overhaul it made in April, prompted by a flood of AI-generated submissions and now asking for a concise reproducer over the long writeups AI churns out.

    Google’s Big Sleep agent reported a run of FFmpeg bugs last year, now visible on the project’s security page tagged BIGSLEEP, and Anthropic’s Mythos model pulled a 16-year-old H.264 flaw and others out of FFmpeg for about $10,000, three of which shipped in FFmpeg 8.1, per its own writeup.

    Days ago, another autonomous tool found an authenticated RCE in Redis that had been present since version 7.2.0, unnoticed for over two years. The research points the same way: a February study had an agent reproduce working PoCs for more than half of 100 real Linux kernel N-day bugs, beating fuzzing.

    Cybersecurity

    For FFmpeg, pull the fixed upstream build or your distribution’s security update as soon as it lands, and prioritize anything that ingests untrusted RTSP or AV1-over-RTP. FFmpeg is widely bundled in media pipelines, Python wheels, container images, and appliances, so do not stop at system packages; those embedded copies need patching too.

    For Chrome, update to 149.0.7827.53 on Linux or 149.0.7827.53/54 on Windows and macOS, or confirm auto-update has run.

    The response has to match the new pace: shorter patch cycles, auto-update wherever it exists, and dependency bumps that carry CVE fixes treated as security work, not routine maintenance.

    The hard part is shifting, though. Finding these bugs has gotten cheap; triaging the reports, shipping the fixes, and getting them installed has not, and much of that work still falls to volunteers and a thin layer of human triagers now expected to keep pace with machines.

    agent bugs Chrome FFmpeg Patches record Uncovers ZeroDays
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleAI is rewriting the logic of management
    Next Article Congress still can’t decide what to do about warrantless surveillance
    admin
    • Website

    Related Posts

    Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available

    June 6, 2026

    Meta’s AI support agent bound recovery emails for anyone who asked. Your SOC never saw an alert.

    June 6, 2026

    IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

    June 5, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    YouTuber and Wife Ended Pregnancy After Down Syndrome Diagnosis. They Got Death Threats.

    Man dies in Western Australia after shark attack | News

    Could you be the FT’s new stock picking champion?

    Transfer rumors, news: Bayern’s Olise is Real Madrid target for Perez

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by