Top stories.
- Researchers find that only a quarter of AI-generated patches are fully successful.
- Ransomware attacks exploit critical N-able flaw.
- LexisNexis disables some services following suspicious activity.
Researchers find that only a quarter of AI-generated patches are fully successful.
Researchers at 1Password found that AI-generated security patches are still largely unreliable, CyberScoop reports. When ChatGPT 5.5 and Claude Opus 4.8 were tested against six recently disclosed vulnerabilities, generating over six thousand patches, only 26% of the patches fully fixed the vulnerability without introducing new problems or altering application behavior. More than half of the time, the AI did not fix the flaw or introduced new vulnerabilities in the process.
The researchers conclude that “human expertise still plays an essential role in the process of fully resolving vulnerabilities in software without introducing unwanted side effects.”
Ransomware attacks exploit critical N-able flaw.
Microsoft has warned that a China-based cybercriminal gang is launching ransomware attacks by exploiting a critical vulnerability in N-able’s N-central software, a widely used remote monitoring and management tool, The Record reports. After exploiting the flaw to gain administrative access, the hackers deploy a new ransomware strain called "StormEncryptor.”
N-able released emergency patches earlier this month after the flaw was observed being exploited in zero-day attacks. The company then issued a second emergency hotfix on August 6th after attackers bypassed the first patch.
LexisNexis disables some services following suspicious activity.
Data analytics company LexisNexis has taken its Diligence, Metabase API, and Newsdesk services offline after detecting suspicious activity on servers managed by a third-party vendor, BleepingComputer reports. The company is investigating the issue and rebuilding the affected systems in a new environment before restoring service. The company hasn’t said whether customer data was compromised. Todd Larsen, president of the global Nexis Solutions division of LexisNexis, said in a statement, “Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation.”