This paper, published on arXiv under the AI Safety framework, introduces a new cryptographic technique called "Function Privatization" designed for the local differential privacy model. The core…
arXiv: HoF-Bench: Rediscovering Real AI-Discovered CVEs Without Frontier Models
AI_SAFETY. Sourced from arxiv_cscr, summarised by Matproof.
AI Analysis
What changed and what to do.
This paper, published on arXiv, presents a new benchmark called HoF-Bench, which demonstrates that open-source, non-frontier AI models can rediscover real-world, previously AI-discovered Common Vulnerabilities and Exposures (CVEs). The key finding is that the capability to autonomously identify and exploit software vulnerabilities is not exclusive to advanced frontier models, but is now accessible to a wider range of AI systems. This effectively lowers the barrier for automated vulnerability discovery and exploitation, shifting the threat landscape.
The primary affected organizations are those in critical infrastructure, software development, and cybersecurity sectors, particularly any entity relying on the assumption that only state-of-the-art AI poses a significant automated threat. Compliance teams in financial services, healthcare, and technology firms should reassess their risk models, as the paper implies that a broader set of actors can now conduct automated vulnerability research. This may impact supply chain security assessments and internal vulnerability management programs.
Compliance teams should immediately review their organization's vulnerability disclosure and patch management policies to account for an increased speed of automated discovery. They should also update their AI governance frameworks to include risk assessments for open-source models used in development or security testing. Finally, teams should engage with their cybersecurity peers to evaluate whether current penetration testing and red-teaming assumptions need to be adjusted in light of this demonstrated capability.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More AI_SAFETY updates
Latest in AI_SAFETY.
This paper, published on arXiv in July 2026, introduces a novel technical approach called "On-Policy Distillation" for improving the safety of large language models (LLMs). Rather than retraining a…
This publication introduces MemSecBench, a new benchmark framework designed to systematically test and measure memory poisoning vulnerabilities in AI agents. Memory poisoning occurs when an attacker…
A new research paper, AgentSnare, has been published on arXiv that introduces a framework for defending against autonomous penetration testing agents. This is not a regulatory change itself, but it…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.