<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing.]]></title><description><![CDATA[<p>There's serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing.  Automated vulnerability hype train again, basically.</p><p>A thread on a few of them.</p>]]></description><link>https://board.circlewithadot.net/topic/4955da9a-5e35-4905-a747-0f074a5ef9fe/there-s-serious-panic-being-caused-by-ai-discovered-vulnerabilities-behind-the-scenes-where-those-finding-them-are-basically-using-them-as-marketing.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 02:51:19 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/4955da9a-5e35-4905-a747-0f074a5ef9fe.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 14 May 2026 11:09:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:32:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> ... also never turn off ASLR! Why would someone do that nowadays!?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/draeath/statuses/116572706541044488</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/draeath/statuses/116572706541044488</guid><dc:creator><![CDATA[draeath@infosec.exchange]]></dc:creator><pubDate>Thu, 14 May 2026 11:32:19 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:27:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> and that's why I'm here. Thanx for keeping us calm.</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/fatalisticcritic/statuses/116572687574926373</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/fatalisticcritic/statuses/116572687574926373</guid><dc:creator><![CDATA[fatalisticcritic@cyberplace.social]]></dc:creator><pubDate>Thu, 14 May 2026 11:27:30 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:25:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> but but but, how else am I supposed to market magic box triage-as-a-service <img class="not-responsive emoji" src="https://media.infosec.exchange/infosec.exchange/custom_emojis/images/000/590/755/original/a162f42ad194baa9.png" title=":neobot_pleading:" /> <img class="not-responsive emoji" src="https://media.infosec.exchange/infosec.exchange/custom_emojis/images/000/170/666/original/8524fc523c29052b.png" title=":blobcatupsidedown:" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/nyanbinary/statuses/116572680434284973</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/nyanbinary/statuses/116572680434284973</guid><dc:creator><![CDATA[nyanbinary@infosec.exchange]]></dc:creator><pubDate>Thu, 14 May 2026 11:25:41 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:25:29 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> I'd be willing to bet that if they paid real humans the same amount of money as the true cost of running the LLM, they'd find more and better bugs.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/womble/statuses/116572679678651080</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/womble/statuses/116572679678651080</guid><dc:creator><![CDATA[womble@infosec.exchange]]></dc:creator><pubDate>Thu, 14 May 2026 11:25:29 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:24:29 GMT]]></title><description><![CDATA[<p>I will likely be one of the first people banging the drum to patch and mitigate if any of the recent AI vulns results in serious harm.  Otherwise, keep calm and carry on patching as usual.</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/GossiTheDog/statuses/116572675730952599</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/GossiTheDog/statuses/116572675730952599</guid><dc:creator><![CDATA[gossithedog@cyberplace.social]]></dc:creator><pubDate>Thu, 14 May 2026 11:24:29 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:22:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> I already feel so "boy who cried wolf"ed about all the vulns</p>]]></description><link>https://board.circlewithadot.net/post/https://meow.social/users/robinsyl/statuses/116572668576024730</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://meow.social/users/robinsyl/statuses/116572668576024730</guid><dc:creator><![CDATA[robinsyl@meow.social]]></dc:creator><pubDate>Thu, 14 May 2026 11:22:40 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:20:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xtero%40ohai.social">@<span>0xtero</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Meanwhile </p><p>1. AI coding agents are one of the factors contributing to shorter intervals between “vulnerability discovery” and “working exploit”</p><p>2. Orgs can’t be bothered to patch known vulnerabilities in a timely fashion so a huge proportion of cyberattacks and their associated damage are down to bugs that have been known about (and left unpatched) for half a year or more</p>]]></description><link>https://board.circlewithadot.net/post/https://twit.social/users/MisuseCase/statuses/116572661097233110</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://twit.social/users/MisuseCase/statuses/116572661097233110</guid><dc:creator><![CDATA[misusecase@twit.social]]></dc:creator><pubDate>Thu, 14 May 2026 11:20:46 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:19:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> <br />(except fewer)</p>

<div class="row mt-3"><div class="col-12 mt-3"><div class="ratio ratio-16x9">
<video controls width="336" height="188">
<source src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/572/655/412/541/631/original/2b080eabd8b45fcf.mp4" type="video/mp4"></source>
</video>
</div></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116572657032151193</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116572657032151193</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Thu, 14 May 2026 11:19:44 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:19:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> while they can certainly find some fun things, a number of the "vulns" are ridiculous "Oh this can be an RCE during full moons with ASLR disabled running on TRSDOS ported to ARM."</p><p>The models don't really threat model well at all. I like <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> 's approach of VULN-DISCLOSURE-POLICY.md</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/mikesiegel/statuses/116572656293225699</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/mikesiegel/statuses/116572656293225699</guid><dc:creator><![CDATA[mikesiegel@infosec.exchange]]></dc:creator><pubDate>Thu, 14 May 2026 11:19:32 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:17:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/misusecase%40twit.social">@<span>MisuseCase</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> most of the stuff is just pure  marketing fluff. Sure, AI is finding bugs. People are fixing them. This has been the case for a while now. Nothing new. Exploitable bugs still very rare. Catastrophic ones like Heartbleed nil, so far. It’s business as usual. The noise volume is up, quality of the signal seems about same as always.</p>]]></description><link>https://board.circlewithadot.net/post/https://ohai.social/users/0xtero/statuses/116572647330864912</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://ohai.social/users/0xtero/statuses/116572647330864912</guid><dc:creator><![CDATA[0xtero@ohai.social]]></dc:creator><pubDate>Thu, 14 May 2026 11:17:16 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:16:24 GMT]]></title><description><![CDATA[<p>CVE-2026-42945 - Nginx (otherwise branded Nginx Rift)</p><p>It relies on a specific Nginx config to be vulnerable, and for attacker to know or discover the config to exploit it.  To reach RCE, also ASLR needs to have been disabled on the box.</p><p>The PoC they've built specifically disabled ASLR, deploys a specifically vulnerable config and the exploit knows about the vulnerable config endpoint.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://cyberplace.social/system/media_attachments/files/116/572/637/830/948/345/original/684bf86549dc61a8.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://cyberplace.social/system/media_attachments/files/116/572/643/615/861/086/original/b9a7396629fec05f.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/GossiTheDog/statuses/116572643931253811</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/GossiTheDog/statuses/116572643931253811</guid><dc:creator><![CDATA[gossithedog@cyberplace.social]]></dc:creator><pubDate>Thu, 14 May 2026 11:16:24 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:11:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> I really want to hear your take on this because I’ve heard conflicting things about whether any of the vulnerabilities are serious or not.</p>]]></description><link>https://board.circlewithadot.net/post/https://twit.social/users/MisuseCase/statuses/116572623949148512</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://twit.social/users/MisuseCase/statuses/116572623949148512</guid><dc:creator><![CDATA[misusecase@twit.social]]></dc:creator><pubDate>Thu, 14 May 2026 11:11:19 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. on Thu, 14 May 2026 11:11:16 GMT]]></title><description><![CDATA[<p>CVE-2026-34486 - Tomcat</p><p>- Only exploitable if a certain feature is used, if its endpoint is reachable and if port 4000 is available.  It's pretty niche.</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/GossiTheDog/statuses/116572623784727448</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/GossiTheDog/statuses/116572623784727448</guid><dc:creator><![CDATA[gossithedog@cyberplace.social]]></dc:creator><pubDate>Thu, 14 May 2026 11:11:16 GMT</pubDate></item></channel></rss>