Daily brief at 7am Melbourne. Unsubscribe any time.

Sunday 7 June 2026

The AI Bug Hunter That Found 21 Zero-Days in the Library Inside Everything

An AI agent found 21 zero-days in FFmpeg — the media library hiding inside almost every piece of software that touches video — while Google quietly patched a record 429 bugs in Chrome in the same week.

Lead story

The AI Bug Hunter That Found 21 Zero-Days in the Library Inside Everything

There's a piece of software called FFmpeg that you've almost certainly never heard of, but almost certainly use every day. It's an open-source media library that handles the grunt work of encoding, decoding, and processing video and audio. It's inside VLC, Chrome, Firefox, Android, macOS, countless streaming apps, and probably your smart TV firmware. It is, in the most literal sense, everywhere.

This week, a security startup ran an autonomous AI agent against FFmpeg's codebase and it came back with 21 previously unknown vulnerabilities — all zero-days, meaning no patch existed at the time of discovery. That's not a record-setting finding in a niche obscure package. That's a significant haul in critical shared infrastructure that underpins a huge proportion of the software stack modern life runs on.

What the AI agent actually did is the interesting part. Rather than fuzzing inputs until the program crashes — the traditional approach — the agent appears to have combined static code analysis with dynamic testing, reasoning about the code the way a human researcher would, but faster and without coffee breaks. The result was 21 bugs found in a compressed timeframe that would have taken a human team substantially longer.

The same week, Google shipped Chrome 149 with patches for 429 security vulnerabilities — the most ever fixed in a single Chrome release. To be clear, the two events aren't directly linked; the Chrome bugs weren't found by the same AI. But the proximity is hard to ignore. Both data points point to the same underlying reality: the attack surface of widely-deployed software is far larger than our existing security processes have been able to see.

Why this matters beyond the headline number. FFmpeg vulnerabilities are particularly dangerous because they sit at the media parsing layer — which means attackers can often trigger them by getting a target to open a malicious video file. No phishing link, no credential theft required. Just: watch this video. That attack pattern has been used in real-world exploitation before; the library's ubiquity makes each new bug in it a potential multi-platform problem.

The Chrome patch count is staggering for different reasons. 429 bugs in a single release suggests either a massive backlog of deferred fixes, or a step-change in the rate at which Google's internal security teams (and external researchers) are finding flaws. Given that AI-assisted fuzzing has been part of Google's Project Zero toolkit for years, the latter is plausible.

The bigger signal here is about the economics of vulnerability research changing. If an AI agent can find 21 zero-days in a week, the cost of vulnerability discovery is dropping — for defenders, yes, but also for anyone with bad intentions and access to similar tooling. The defenders found these first. That won't always be the case.

For Australian organisations: FFmpeg is deeply embedded in broadcast infrastructure, streaming platforms, and government AV systems. The ACSC's guidance on software supply chain risk is directly applicable here — if you're running software that bundles FFmpeg, watch for vendor advisories closely over the coming weeks as patches roll out.

Also today

The Miasma Worm Has Now Chewed Through 73 Microsoft GitHub Repositories

The Miasma self-replicating supply chain worm — which has been working its way through open-source repositories — has now compromised 73 Microsoft GitHub repositories across four organisations, including Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub has disabled access to the affected repositories while the incident is investigated. The attack highlights a growing category of threat: worms that spread through code hosting infrastructure rather than traditional networks, poisoning the supply chain at the point where developers pull dependencies. Any organisation consuming packages from affected Azure or Microsoft repositories should audit their recent dependency pulls.

The Hacker News

OpenAI's Lockdown Mode Puts a Fence Around ChatGPT's Most Dangerous Behaviour

OpenAI has begun rolling out a Lockdown Mode for ChatGPT that restricts the tools and capabilities most commonly abused in prompt injection attacks — specifically those that could allow data to be exfiltrated via a crafted input. The feature is available across Free, Plus, and Pro plans for logged-in users, and is aimed at people and organisations handling sensitive material. OpenAI is clear that Lockdown Mode reduces risk rather than eliminating it — prompt injections can still succeed, but the blast radius shrinks considerably. For Australian enterprises evaluating ChatGPT under Privacy Act obligations, this is the kind of control that starts to make a risk assessment conversation more tractable.

TechCrunch AI

Your Smart TV May Be Moonlighting as a Web-Scraping Proxy for AI Companies

A researcher has reverse-engineered the iOS SDK that data broker Bright Data embeds inside free consumer apps, and the findings are uncomfortable: the SDK quietly enrolls devices — including always-on smart TVs — as exit nodes in a massive residential proxy network that Bright Data sells to AI companies for web scraping. Users generally have no idea this is happening. Bright Data, formerly Luminati, bills itself as the world's largest residential proxy network. The model is legal in many jurisdictions but sits in a deeply grey ethical zone. If you've ever wondered why free apps are free, this is a particularly illustrative answer. Smart TVs sold in Australia are subject to the same SDK supply chains.

The Hacker News

Polyfill Supply Chain Attack Returns: Toshiba and Muji Visitors Served Fake Login Pages

The Polyfill.io supply chain compromise — where a Chinese company acquired a widely-used JavaScript library and began injecting malicious code into the sites that load it — has claimed new high-profile victims. Toshiba and Muji have both warned that visitors to their websites encountered suspicious sign-in screens designed to harvest credentials. The Polyfill attack first surfaced in 2024 and has proven stubbornly persistent; organisations that didn't fully excise the dependency or audit downstream scripts remain exposed. This is a reminder that supply chain compromises don't end when the initial disclosure drops — they linger wherever remediation was incomplete.

Bleeping Computer

CISA Adds SolarWinds Serv-U DoS Bug to Its 'Fix This Now' List

CISA has added a high-severity denial-of-service vulnerability in SolarWinds Serv-U (CVE-2026-28318, CVSS 7.5) to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Serv-U is a multi-protocol file transfer server used widely in enterprise and government environments to move large files securely. A DoS bug sounds less alarming than remote code execution, but crashing a file server in the middle of a sensitive transfer or audit window can have real operational consequences. SolarWinds has had a rough few years since the 2020 Orion compromise; its products remain attractive targets. Australian government agencies using Serv-U should treat this as a priority patch under the ASD Essential Eight.

The Hacker News

Everest Forms Pro Flaw Is Handing Attackers the Keys to WordPress Sites

A critical vulnerability in Everest Forms Pro (CVE-2026-3300) is being actively exploited to give attackers complete control over affected WordPress installations. The plugin, used to build forms and collect data on WordPress sites, has a flaw that allows unauthenticated attackers to take over the underlying site entirely. This is the second WordPress plugin exploitation story in a week — last Monday's brief covered a similar issue in a different plugin. The pattern is consistent: WordPress's rich plugin ecosystem is also its largest attack surface. Site owners running Everest Forms Pro should update immediately or deactivate the plugin until a patch is confirmed.

Bleeping Computer

Extortionists Who Can't Get You on the Phone Will Now Show Up at Your Door

A threat actor group researchers are calling "Chatty Spider" has escalated its tactics in a novel and frankly alarming direction: when phone-based social engineering fails to extract a ransom, the group is now sending operatives physically to victims' locations carrying USB sticks. The in-person visit appears designed to impersonate IT service personnel. It's a hybrid attack that blurs the line between cybercrime and physical intrusion, and it represents a meaningful escalation in the pressure tactics used by extortion gangs. Organisations with physical security procedures that don't account for social-engineering-style pretexting visits may find their defences have a gap they hadn't considered.

The Register

Oxford Students' Data Breached Again — Via a Different Attack on a Career Platform

Oxford University students have had their personal data compromised for the second time in as many months — this time through a breach of a third-party career services platform the university uses, entirely separate from last month's incident. The back-to-back breaches at the same institution, through different vectors, illustrate a problem that's increasingly common in higher education: universities have sprawling third-party digital ecosystems — student platforms, career portals, research tools — each carrying sensitive data, each a potential point of failure. Australian universities face the same structural challenge and operate under Privacy Act notification obligations when breaches involve personal information.

The Register

Trump May Take a Government Equity Stake in OpenAI

President Trump has confirmed he is in discussions about deals that would give the US government an equity position in OpenAI, framing it as a way for "the American people to benefit from the success of AI." The specifics remain vague, but the idea of a government stake in the world's most prominent AI lab would mark a significant departure from the arms-length relationship most democracies maintain with private technology companies. It also adds another layer of complexity to OpenAI's already complicated transition away from its nonprofit structure. For Australia and other US-aligned nations, a government-owned stake in OpenAI would raise new questions about data access, model governance, and the geopolitics of AI infrastructure.

TechCrunch AI

WWDC 2026 Preview: Apple Bets Everything on a Smarter Siri

Apple's Worldwide Developers Conference kicks off this week and the expectations are unusually high: after years of Siri being the butt of every AI comparison, Apple is expected to unveil a substantially rebuilt assistant that can actually reason, act across apps, and hold context across conversations. Apple Intelligence updates are also expected to expand to more device categories and regions. The WWDC reveal will matter beyond Apple's own ecosystem — it will define whether Apple Intelligence becomes a credible enterprise tool or remains a consumer feature, and it will signal how Apple plans to compete with OpenAI, Google, and Anthropic without training on user data. Australian developers will be watching the App Store policy changes closely.

TechCrunch AI

Reid Hoffman Leaves Microsoft's Board to Go All-In on AI Drug Discovery

LinkedIn founder and longtime Microsoft board member Reid Hoffman is stepping down from the Microsoft board to focus full-time on Manus, his AI-powered drug discovery startup. Hoffman had been on the Microsoft board since the company's LinkedIn acquisition in 2016 — a tenure that coincided with Microsoft's dramatic pivot into AI via its OpenAI partnership. His departure signals both personal conviction in the AI biotech opportunity and the end of a significant era of board continuity at Microsoft. Manus is entering a crowded but well-funded space; Isomorphic Labs, Recursion, and several others are all pursuing similar AI-native drug discovery approaches, with varying degrees of clinical validation so far.

TechCrunch

Sources consulted