ZeroHour

Search: “deception”

2,037 stories

AWS puts AI vulnerability detection to the test, and false positives pile up

AWS publicly released its Deception Benchmark (14,822 samples) showing leading AI models falsely flag 41-99% of safe code as vulnerable.

AWS released its Deception Benchmark publicly, containing 14,822 samples across 16 programming languages and more than 70 CWE categories, with 9,695 scored samples split into 6,988 code-level and 2,707 environment-gated challenges. AWS evaluated 12 models from five providers using single-turn prompts and found none met its production bar of below 10% for both false-positive and false-negative rates. With direct prompting, models caught nearly all real vulnerabilities but incorrectly flagged 41% to 99% of safe code, with precision between 52% and 71%. Asking models to prove exploitability reduced false positives by 17 to 74 percentage points but raised false-negative rates to 7-44%, with models struggling most when external controls like Kubernetes Network Policies blocked apparent exploits.

Help Net Security · 2d agoAI research

A new class action lawsuit questions whether Anthropic broke the law by misleading power users

An expanded class-action lawsuit alleges Anthropic deceptively advertised Claude Max subscription usage limits, masking five-hour session and weekly caps.

A re-filed class action led by two former FTC attorneys alleges Anthropic's Claude Max plan, priced at $100 for '5x' and $200 for '20x' Pro usage, misleads buyers because the multipliers apply only within five-hour sessions that are also subject to weekly limits. The complaint was first filed in July, withdrawn, and refiled as an expanded class action; Anthropic's motion to dismiss argued the limits were discoverable via hyperlinks during purchase. Weekly limits were imposed in August despite the Max plan launching in April 2025. Anthropic did not respond to requests for comment.

The Verge · AI · 8d agoAI industry