New AI Vulnerability Scoring System Introduced at OWASP Global AppSec
Article Content
Browse articles
At the OWASP Global AppSec conference on November 7, 2025, Ken Huang announced the AI Vulnerability Scoring System (AIVSS), designed to address limitations in the Common Vulnerability Scoring System (CVSS) for evaluating vulnerabilities in agentic AI. This new framework aims to provide a more accurate assessment of vulnerabilities in modern AI technologies, which traditional models struggle to evaluate effectively.
Ask AI about this cluster
Answers cite the sources they use
Updated 192d ago How this analysis works
More articles in this cluster (3)
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Log4j2 Deserialization Bypass Enables Remote Code Execution Recent research has revealed a vulnerability in Apache Log4j2 that allows remote code execution (RCE) through unsafe Java deserialization. The issue affects versions 2.11.0 to 2.26.1 of log4j-api and 2.8.0 to 2.26.1 of log4j-core, specifically in configurations that deserialize serialized LogEvent objects from…