Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageAI Security Desk
AI Security

COGNITION: From Evaluation to Defense against Multimodal LLM CAPTCHA Solvers

Large language models can now bypass visual CAPTCHAs at scale, fundamentally undermining a core web security assumption relied upon by enterprise authentication flows.

Summary written by editorial AI · Source link below

Filed by arXiv Crypto & Security1 min readRead at source ↗

arXiv:2512.02318v4 Announce Type: replace Abstract: This paper studies how multimodal large language models (MLLMs) undermine the security guarantees of visual CAPTCHA. We identify the attack surface where an adversary can cheaply automate CAPTCHA solving using off-the-shelf models. We evaluate 7 representative MLLMs on 18 real-world CAPTCHA task types, measuring single-shot accuracy, success under limited retries, end-to-end latency, and per-solve cost. We further validate our findings through

Editorial Analysis

Why it matters

Organizations relying on CAPTCHA as a bot protection layer may face automated attacks that bypass this defense entirely, requiring immediate authentication strategy review.

What to do

Audit web applications using CAPTCHA-only bot protection and implement multi-layered behavioral detection mechanisms.

Board brief

Traditional bot protection methods are becoming obsolete as AI systems can now solve visual puzzles designed to distinguish humans from machines.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at arXiv Crypto & Security

External link — opens at arXiv Crypto & Security in a new tab.

§
Continue with

More from the AI Security Desk