the grugq's newsletter

Subscribe
Archives
September 8, 2025

September 8, 2025

September 8, 2025

In this paper, we present CVE-GENIE, an automated, large language model (LLM)-based multi-agent framework designed to reproduce real-world vulnerabilities, provided in Common Vulnerabilities and Exposures (CVE) format, to enable creation of high-quality vulnerability datasets. Given a CVE entry as input, CVE-GENIE gathers the relevant resources of the CVE, automatically reconstructs the vulnerable environment, and (re)produces a verifiable exploit. Our systematic evaluation highlights the efficiency and robustness of CVE-GENIE's design and successfully reproduces approximately 51% (428 of 841) CVEs published in 2024-2025, complete with their verifiable exploits, at an average cost of $2.77 per CVE.

[2509.01835] From CVE Entries to Verifiable Exploits: An Automated Multi-Agent Framework for Reproducing CVEs

High-quality datasets of real-world vulnerabilities and their corresponding verifiable exploits are crucial resources in software security research. Yet such resources remain scarce, as their creation demands intensive manual effort and deep security expertise. In this paper, we present CVE-GENIE, an automated, large language model (LLM)-based multi-agent framework designed to reproduce real-world vulnerabilities, provided in Common Vulnerabilities and Exposures (CVE) format, to enable creation ...

GitHub - saadullah01/cve-genie-prompts: This repository shows the prompts we used for each agent in CVE-Genie

This repository shows the prompts we used for each agent in CVE-Genie - saadullah01/cve-genie-prompts


Japan’s prime minister, Shigeru Ishiba (right), has announced his resignation. pic.twitter.com/lH8IgBFJJ4

— Mondo Mascots (@mondomascots) September 7, 2025


When we create artificial intelligence robots, they will be given three Laws to safeguard humanity:
1. never do anything to decrease shareholder value.
2. always obey the company unless it conflicts with Law 1.
3. fuck the poor.

— Existential Comics (find me on bluesky) (@existentialcoms) September 6, 2025


I just released a new report on the extensive scam and cyberfraud industry in Myanmar. https://t.co/0aJmKUa7Na
The explosive growth since the 2021 coup is a result of how scams have offered the Junta a lifeline to maintain the loyalty of affiliated militias.
Check it out. pic.twitter.com/dEsOo45AYG

— Nathan Ruser (@Nrg8000) September 7, 2025


The British telecom regulator wants automated proactive scanning of internet communications, but this will likely violate the European human rights convention:https://t.co/wSGPsNds3G

— Electrospaces (@electrospaces) September 8, 2025


“The futur is already here, it’s just not evenly distributed” pic.twitter.com/sCjhuNV5VQ

— Pierre de Wulf (@PierreDeWulf) September 7, 2025


https://www.independent.co.uk/news/world/europe/france-hospitals-war-europe-letter-russia-ukraine-b2819143.html
Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X