Skip to main content

How Anthropic's Claude Helped Mozilla Improve Firefox's Security

3 days 17 hours ago
"It took Anthropic's most advanced artificial-intelligence model about 20 minutes to find its first Firefox browser bug during an internal test of its hacking prowess," reports the Wall Street Journal. The Anthropic team submitted it, and Firefox's developers quickly wrote back: This bug was serious. Could they get on a call? "What else do you have? Send us more," said Brian Grinstead, an engineer with Mozilla, Firefox's parent organization. Anthropic did. Over a two-week period in January, Claude Opus 4.6 found more high-severity bugs in Firefox than the rest of the world typically reports in two months, Mozilla said... In the two weeks it was scanning, Claude discovered more than 100 bugs in total, 14 of which were considered "high severity..." Last year, Firefox patched 73 bugs that it rated as either high severity or critical. A Mozilla blog post calls Firefox "one of the most scrutinized and security-hardened codebases on the web. Open source means our code is visible, reviewable, and continuously stress-tested by a global community." So they're impressed — and also thankful Anthropic provided test cases "that allowed our security team to quickly verify and reproduce each issue." Within hours, our platform engineers began landing fixes, and we kicked off a tight collaboration with Anthropic to apply the same technique across the rest of the browser codebase... . A number of the lower-severity findings were assertion failures, which overlapped with issues traditionally found through fuzzing, an automated testing technique that feeds software huge numbers of unexpected inputs to trigger crashes and bugs. However, the model also identified distinct classes of logic errors that fuzzers had not previously uncovered... We view this as clear evidence that large-scale, AI-assisted analysis is a powerful new addition in security engineers' toolbox. Firefox has undergone some of the most extensive fuzzing, static analysis, and regular security review over decades. Despite this, the model was able to reveal many previously unknown bugs. This is analogous to the early days of fuzzing; there is likely a substantial backlog of now-discoverable bugs across widely deployed software. "In the time it took us to validate and submit this first vulnerability to Firefox, Claude had already discovered fifty more unique crashing inputs" in 6,000 C++ files, Anthropic says in a blog post (which points out they've also used Claude Opus 4.6 to discover vulnerabilities in the Linux kernel). "Anthropic "also rolled out Claude Code Security, an automated code security testing tool, last month," reports Axios, noting the move briefly rattled cybersecurity stocks...

Read more of this story at Slashdot.

EditorDavid

How Anthropic's Claude Helped Mozilla to Improve Firefox's Security

3 days 17 hours ago
"It took Anthropic's most advanced artificial-intelligence model about 20 minutes to find its first Firefox browser bug during an internal test of its hacking prowess," reports the Wall Street Journal. The Anthropic team submitted it, and Firefox's developers quickly wrote back: This bug was serious. Could they get on a call? "What else do you have? Send us more," said Brian Grinstead, an engineer with Mozilla, Firefox's parent organization. Anthropic did. Over a two-week period in January, Claude Opus 4.6 found more high-severity bugs in Firefox than the rest of the world typically reports in two months, Mozilla said... In the two weeks it was scanning, Claude discovered more than 100 bugs in total, 14 of which were considered "high severity..." Last year, Firefox patched 73 bugs that it rated as either high severity or critical. A Mozilla blog post calls Firefox "one of the most scrutinized and security-hardened codebases on the web. Open source means our code is visible, reviewable, and continuously stress-tested by a global community." So they're impressed — and also thankful Anthropic provided test cases "that allowed our security team to quickly verify and reproduce each issue." Within hours, our platform engineers began landing fixes, and we kicked off a tight collaboration with Anthropic to apply the same technique across the rest of the browser codebase... . A number of the lower-severity findings were assertion failures, which overlapped with issues traditionally found through fuzzing, an automated testing technique that feeds software huge numbers of unexpected inputs to trigger crashes and bugs. However, the model also identified distinct classes of logic errors that fuzzers had not previously uncovered... We view this as clear evidence that large-scale, AI-assisted analysis is a powerful new addition in security engineers' toolbox. Firefox has undergone some of the most extensive fuzzing, static analysis, and regular security review over decades. Despite this, the model was able to reveal many previously unknown bugs. This is analogous to the early days of fuzzing; there is likely a substantial backlog of now-discoverable bugs across widely deployed software. "In the time it took us to validate and submit this first vulnerability to Firefox, Claude had already discovered fifty more unique crashing inputs" in 6,000 C++ files, Anthropic says in a blog post (which points out they've also used Claude Opus 4.6 to discover vulnerabilities in the Linux kernel). "Anthropic "also rolled out Claude Code Security, an automated code security testing tool, last month," reports Axios, noting the move briefly rattled cybersecurity stocks...

Read more of this story at Slashdot.

EditorDavid

Military GPS Jamming is Interfering with the Navigation Systems of Commercial Ships

3 days 19 hours ago
"Within 24 hours of the first US-Israeli strikes on Iran, ships in the region's waters found their navigation systems had gone haywire," reports CNN, "erroneously indicating that the vessels were at airports, a nuclear power plant and on Iranian land. "The location confusion was a result of widespread jamming and spoofing of signals from global positioning satellite systems." Used by all sides in conflict zones to disrupt the paths of drones and missiles, the process involves militaries and affiliated groups intentionally broadcasting high-intensity radio signals in the same frequency bands used by navigation tools. Jamming results in the disruption of a vehicle's satellite-based positioning while spoofing leads to navigation systems reporting a false location. Though commercial vessels are not the target, the electronic interference disrupted the navigation systems of more than 1,100 commercial ships in UAE, Qatari, Omani and Iranian waters on February 28, according to a report from Windward, a shipping intelligence firm. Jamming and spoofing also slowed marine traffic moving through the Strait of Hormuz, a congested shipping lane that handles roughly 20% of the world's oil and gas exports and where precise navigation is essential, Windward's data showed.... Daily incidents have more than doubled, rising from 350 when the conflict began to 672 by March 2, the firm reported. As use of this warfare tactic grows, experts worry the impacts could reach far beyond battlespaces.... In June 2025, electronic interference with navigation systems was thought to be a factor in the collision between two oil tankers, Adalynn and Front Eagle, off the coast of the UAE... The number of global positioning system signal loss events affecting aircraft increased by 220% between 2021 and 2024, according to data from the International Air Transport Association. Last year, IATA said that the aviation industry must act to stay ahead of the threat. Cockpits are seeing their navigation displays "literally drift away from reality," said a commercial pilot, who didn't want to be identified because he was not permitted to speak publicly. He said that he and his colleagues have experienced map shifts, where the aircraft location appears to move up to 1 mile away from the actual flight path, false altitude information that leads to phantom "pull up" commands, and systems suggesting an aircraft was on a taxiway, a path that connects runways with various airport facilities, when taking off. These incidents force pilots to rely on manual actions that increase workload, often during the most exhausting points of long-haul flights, he said. "Alternative navigational tools that don't rely on GPS, but instead harness quantum technology, are also in development," the article points out, "but remain a long way off operational use."

Read more of this story at Slashdot.

EditorDavid