oh my FUCKING GOD https://github.com/v12-security/pocs/tree/main/fragnesia-5db89c99566fc
-
oh my FUCKING GOD https://github.com/v12-security/pocs/tree/main/fragnesia-5db89c99566fc
@cadey just keep on patching lmao
im REALLY happy i had automated patching properly setup the last few weeks
-
@cadey just keep on patching lmao
im REALLY happy i had automated patching properly setup the last few weeks
@cadey are these things even getting CVEs?
or coordinated disclosure?
or are these just AI-found bugs people are like "lmao, lemme add to the pile"
-
@cadey are these things even getting CVEs?
or coordinated disclosure?
or are these just AI-found bugs people are like "lmao, lemme add to the pile"
-
@cadey are these things even getting CVEs?
or coordinated disclosure?
or are these just AI-found bugs people are like "lmao, lemme add to the pile"
@ShadowJonathan@tech.lgbt @cadey@pony.social they are getting cves but the disclosure happens as the patch is made (not merged).
-
@xerz @ShadowJonathan @cadey so in case those are ai-found bugs, the reasoning for publishing those immediately is, that anybody else with access to an AI could exploit them, so everybody is probably on the safer side to assume that everything found with those tools are zero-days now.
-
oh my FUCKING GOD https://github.com/v12-security/pocs/tree/main/fragnesia-5db89c99566fc
@cadey gvisor / vms and carry on. At least until they start dumping vulns for those as well

-
oh my FUCKING GOD https://github.com/v12-security/pocs/tree/main/fragnesia-5db89c99566fc
@cadey oh gosh ... this is getting out of control
... going to be a hell of crazy year -
@cadey are these things even getting CVEs?
or coordinated disclosure?
or are these just AI-found bugs people are like "lmao, lemme add to the pile"
@ShadowJonathan @cadey
The kernel just updated their guidelines for security issue reporting today; any bugs found via "AI assistance" are to be treated as public. -
oh my FUCKING GOD https://github.com/v12-security/pocs/tree/main/fragnesia-5db89c99566fc
@cadey no such thing as responsible disclosure in the world of AI bullshit huh
-
@ShadowJonathan @cadey
The kernel just updated their guidelines for security issue reporting today; any bugs found via "AI assistance" are to be treated as public.@sudoBash418 @ShadowJonathan @cadey Unsure if that was a good idea.
-
R relay@relay.mycrowd.ca shared this topic