Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

Scheduled Pinned Locked Moved Uncategorized
24 Posts 21 Posters 67 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • jonty@chaos.socialJ This user is from outside of this forum
    jonty@chaos.socialJ This user is from outside of this forum
    jonty@chaos.social
    wrote last edited by
    #1

    Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

    Link Preview Image
    issyl0@ruby.socialI jcoglan@mastodon.socialJ kkarhan@infosec.spaceK cy@chaos.socialC jarkman@chaos.socialJ 17 Replies Last reply
    3
    0
    • jonty@chaos.socialJ jonty@chaos.social

      Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

      Link Preview Image
      issyl0@ruby.socialI This user is from outside of this forum
      issyl0@ruby.socialI This user is from outside of this forum
      issyl0@ruby.social
      wrote last edited by
      #2

      @jonty what

      1 Reply Last reply
      0
      • jonty@chaos.socialJ jonty@chaos.social

        Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

        Link Preview Image
        jcoglan@mastodon.socialJ This user is from outside of this forum
        jcoglan@mastodon.socialJ This user is from outside of this forum
        jcoglan@mastodon.social
        wrote last edited by
        #3

        @jonty I got a vulnerability for you: mixing latin and greek terms in the same phrase

        endlessmason@hachyderm.ioE 1 Reply Last reply
        0
        • jonty@chaos.socialJ jonty@chaos.social

          Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

          Link Preview Image
          kkarhan@infosec.spaceK This user is from outside of this forum
          kkarhan@infosec.spaceK This user is from outside of this forum
          kkarhan@infosec.space
          wrote last edited by
          #4

          @jonty if this were to happen to me I'd press charges for blackmail, extortion whilst notifying said platforms to quick-freeze records as they'll be listed as withnesses for the police to collect evidence from.

          • Also I'd publicly #NameThemBlameThem and ban them from my projects.
            • As I did in more than one case.
          badsamurai@infosec.exchangeB 1 Reply Last reply
          0
          • jonty@chaos.socialJ jonty@chaos.social

            Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

            Link Preview Image
            issyl0@ruby.socialI This user is from outside of this forum
            issyl0@ruby.socialI This user is from outside of this forum
            issyl0@ruby.social
            wrote last edited by
            #5

            @jonty I escalated to the spam team and the account is now ⚰️.

            jonty@chaos.socialJ impulse9@chaos.socialI 2 Replies Last reply
            0
            • issyl0@ruby.socialI issyl0@ruby.social

              @jonty I escalated to the spam team and the account is now ⚰️.

              jonty@chaos.socialJ This user is from outside of this forum
              jonty@chaos.socialJ This user is from outside of this forum
              jonty@chaos.social
              wrote last edited by
              #6

              @issyl0 I did wonder how that happened so quickly after me posting here! Thank you!

              I've just raised a complaint at Stripe too, so hopefully that will nuke the account there before anyone is taken in.

              1 Reply Last reply
              0
              • jonty@chaos.socialJ jonty@chaos.social

                Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

                Link Preview Image
                cy@chaos.socialC This user is from outside of this forum
                cy@chaos.socialC This user is from outside of this forum
                cy@chaos.social
                wrote last edited by
                #7

                @jonty ai beg bounty. seeing this a lot lately on security.txt contact mails also 💔

                1 Reply Last reply
                0
                • jonty@chaos.socialJ jonty@chaos.social

                  Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

                  Link Preview Image
                  jarkman@chaos.socialJ This user is from outside of this forum
                  jarkman@chaos.socialJ This user is from outside of this forum
                  jarkman@chaos.social
                  wrote last edited by
                  #8

                  @jonty what a shitty business model!

                  1 Reply Last reply
                  0
                  • jcoglan@mastodon.socialJ jcoglan@mastodon.social

                    @jonty I got a vulnerability for you: mixing latin and greek terms in the same phrase

                    endlessmason@hachyderm.ioE This user is from outside of this forum
                    endlessmason@hachyderm.ioE This user is from outside of this forum
                    endlessmason@hachyderm.io
                    wrote last edited by
                    #9

                    @jcoglan @jonty
                    Another vulnerability: not doing plural(s) correctly

                    1 Reply Last reply
                    0
                    • R relay@relay.an.exchange shared this topic
                    • kkarhan@infosec.spaceK kkarhan@infosec.space

                      @jonty if this were to happen to me I'd press charges for blackmail, extortion whilst notifying said platforms to quick-freeze records as they'll be listed as withnesses for the police to collect evidence from.

                      • Also I'd publicly #NameThemBlameThem and ban them from my projects.
                        • As I did in more than one case.
                      badsamurai@infosec.exchangeB This user is from outside of this forum
                      badsamurai@infosec.exchangeB This user is from outside of this forum
                      badsamurai@infosec.exchange
                      wrote last edited by
                      #10

                      @kkarhan @jonty strongly in favor of this. They are committing crimes.

                      kkarhan@infosec.spaceK 1 Reply Last reply
                      0
                      • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                        @kkarhan @jonty strongly in favor of this. They are committing crimes.

                        kkarhan@infosec.spaceK This user is from outside of this forum
                        kkarhan@infosec.spaceK This user is from outside of this forum
                        kkarhan@infosec.space
                        wrote last edited by
                        #11

                        @badsamurai @jonty reminds me of #Certik holding #Shitcoins from #Kraken in a very unethicalcway after successfully being able to get some...

                        1 Reply Last reply
                        0
                        • mttaggart@infosec.exchangeM mttaggart@infosec.exchange shared this topic
                        • jonty@chaos.socialJ jonty@chaos.social

                          Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

                          Link Preview Image
                          pl@cosocial.caP This user is from outside of this forum
                          pl@cosocial.caP This user is from outside of this forum
                          pl@cosocial.ca
                          wrote last edited by
                          #12

                          @jonty but it has a scan hash!!

                          1 Reply Last reply
                          0
                          • jonty@chaos.socialJ jonty@chaos.social

                            Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

                            Link Preview Image
                            david_chisnall@infosec.exchangeD This user is from outside of this forum
                            david_chisnall@infosec.exchangeD This user is from outside of this forum
                            david_chisnall@infosec.exchange
                            wrote last edited by
                            #13

                            @jonty

                            Some legitimate folks got burned by doing this because asking for money to not do a bad thing meets the legal definition of blackmail, even if it's well intentioned. If they have an actual business that they want you to contact, you may be able to get the police involved.

                            1 Reply Last reply
                            0
                            • issyl0@ruby.socialI issyl0@ruby.social

                              @jonty I escalated to the spam team and the account is now ⚰️.

                              impulse9@chaos.socialI This user is from outside of this forum
                              impulse9@chaos.socialI This user is from outside of this forum
                              impulse9@chaos.social
                              wrote last edited by
                              #14

                              @issyl0 @jonty thank you!

                              1 Reply Last reply
                              0
                              • jonty@chaos.socialJ jonty@chaos.social

                                Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

                                Link Preview Image
                                spaceinvader@social.securitytheater.netS This user is from outside of this forum
                                spaceinvader@social.securitytheater.netS This user is from outside of this forum
                                spaceinvader@social.securitytheater.net
                                wrote last edited by
                                #15

                                @jonty Yeah, I wouldn’t pay $299 for something with only a SHA-256 seal! That’s more than $1/bit.

                                1 Reply Last reply
                                0
                                • R relay@relay.publicsquare.global shared this topic
                                • jonty@chaos.socialJ jonty@chaos.social

                                  Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

                                  Link Preview Image
                                  eatyourgreens@mastodon.socialE This user is from outside of this forum
                                  eatyourgreens@mastodon.socialE This user is from outside of this forum
                                  eatyourgreens@mastodon.social
                                  wrote last edited by
                                  #16

                                  @jonty isn’t extortion a teensy bit illegal in the UK?

                                  rndanger@infosec.exchangeR 1 Reply Last reply
                                  0
                                  • jonty@chaos.socialJ jonty@chaos.social

                                    Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

                                    Link Preview Image
                                    L This user is from outside of this forum
                                    L This user is from outside of this forum
                                    luc0x61@mastodon.gamedev.place
                                    wrote last edited by
                                    #17

                                    @jonty When you have a perfect idiot machine to generate massive scam, why don't?
                                    Here's the real added value of LLMs, where to monetize on.

                                    1 Reply Last reply
                                    0
                                    • jonty@chaos.socialJ jonty@chaos.social

                                      Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

                                      Link Preview Image
                                      guillotine_jones@beige.partyG This user is from outside of this forum
                                      guillotine_jones@beige.partyG This user is from outside of this forum
                                      guillotine_jones@beige.party
                                      wrote last edited by
                                      #18

                                      @jonty
                                      Who said Ai isn't making money?

                                      1 Reply Last reply
                                      0
                                      • jonty@chaos.socialJ jonty@chaos.social

                                        Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

                                        Link Preview Image
                                        n1xnx@tilde.zoneN This user is from outside of this forum
                                        n1xnx@tilde.zoneN This user is from outside of this forum
                                        n1xnx@tilde.zone
                                        wrote last edited by
                                        #19

                                        @jonty
                                        Sounds like criminal extortion to me.
                                        Send a C&D letter and f9ile a complaint with the police? Since it's over the wire, that makes it Federal if it's in the US.

                                        1 Reply Last reply
                                        0
                                        • jonty@chaos.socialJ jonty@chaos.social

                                          Today a bunch of my open-source projects got slammed by incorrect AI-written vulnerability reports demanding $299 for disclosure

                                          Link Preview Image
                                          nobody@mastodon.acm.orgN This user is from outside of this forum
                                          nobody@mastodon.acm.orgN This user is from outside of this forum
                                          nobody@mastodon.acm.org
                                          wrote last edited by
                                          #20

                                          @jonty
                                          "You're in a desert, Leon, walking along in the sand ..."

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups