<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[My hot take on the vulnpocalypse:]]></title><description><![CDATA[<p>My hot take on the vulnpocalypse:</p><p>We don't have more vulnerabilities than we had before. The vulnerabilities were always there, we just didn't know they existed. But importantly, for moderately sophisticated attackers, who only have to find a relatively low number of vulns to begin with, not much has changed. Yeah it's a little bit cheaper, but finding vulns wasn't all that difficult, depending on the target. For defenders otoh, making the finding of vulns cheaper is theoretically a good thing, but we already had not enough capacity to fix the vulns found by fuzz testing and similar methods before, so this is just adding on the pile of stuff we know is broken, but can't keep up with fixing it. The net effect seems to be that we made triage more expensive. Yay.</p>]]></description><link>https://board.circlewithadot.net/topic/60bd5e2e-ccd6-4ffc-88de-c2ea9c41f6fe/my-hot-take-on-the-vulnpocalypse</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 03:37:52 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/60bd5e2e-ccd6-4ffc-88de-c2ea9c41f6fe.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 19 Apr 2026 16:41:22 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to My hot take on the vulnpocalypse: on Mon, 20 Apr 2026 06:59:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/sophieschmieg%40infosec.exchange">@<span>sophieschmieg</span></a></span> <span><a href="/user/fugueish%40wandering.shop">@<span>fugueish</span></a></span> </p><p>Mythos appears to make it significantly cheaper to find vulnerabilities — little to no expertise/sophistication required — copy &amp; paste a prompt and wait. If so, that significantly increases the pool of attackers.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/peymano/statuses/116435736688182272</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/peymano/statuses/116435736688182272</guid><dc:creator><![CDATA[peymano@mastodon.social]]></dc:creator><pubDate>Mon, 20 Apr 2026 06:59:05 GMT</pubDate></item><item><title><![CDATA[Reply to My hot take on the vulnpocalypse: on Sun, 19 Apr 2026 20:04:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/sophieschmieg%40infosec.exchange">@<span>sophieschmieg</span></a></span> 100% agree but I’ve one recent observation to add. Mythos reporting got our C-levels’ attention in a big way. This has had other tangential benefits. For example, our purple team (of which I’m a participant) have for many, many months (nearly two years now) recommended expanding our red team and increasing the number and type of penetration tests to include the company’s new AI “employees.” That was always met with a, “it’ll interfere with business development” denial. This week they came to us and asked how long would it take to ramp up. The plan had already been laid out and all that remains is to get stakeholders’ formal approval to test their new toys. That’s now assured because they are asking for it. It’ll start next week. And while vulns may not always be patched quickly, I feel it really lowers the risk to have a few well informed mitigations in place either via code, policies or SOP. Sometimes a little fear can move the needle in significant ways.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Spartan_1986/statuses/116433163367900386</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Spartan_1986/statuses/116433163367900386</guid><dc:creator><![CDATA[spartan_1986@infosec.exchange]]></dc:creator><pubDate>Sun, 19 Apr 2026 20:04:39 GMT</pubDate></item><item><title><![CDATA[Reply to My hot take on the vulnpocalypse: on Sun, 19 Apr 2026 19:10:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/tess%40mastodon.social">@<span>tess</span></a></span><br />Higher bar for committing code? That sounds like a bottleneck that's going to slow down sales. We don't have time to refine the code we've got! We need to push out new features, then more new products, especially since we can do that much faster now with our machine that rapidly generates vulnerable code!<br /> <span><a href="/user/sophieschmieg%40infosec.exchange">@<span>sophieschmieg</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/115602245324882913/statuses/116432951134195940</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/115602245324882913/statuses/116432951134195940</guid><dc:creator><![CDATA[thief_of_fire@infosec.exchange]]></dc:creator><pubDate>Sun, 19 Apr 2026 19:10:41 GMT</pubDate></item><item><title><![CDATA[Reply to My hot take on the vulnpocalypse: on Sun, 19 Apr 2026 16:58:10 GMT]]></title><description><![CDATA[<p><span><a href="/user/tess%40mastodon.social">@<span>tess</span></a></span> <br />We've been trying for decades <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61e.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--disappointed" style="height:23px;width:auto;vertical-align:middle" title=":(" alt="😞" /> Maybe GenAI will help?  There are still a lot of products/projects out there with lousy testing discipline/coverage though.</p><p><span><a href="/user/sophieschmieg%40infosec.exchange">@<span>sophieschmieg</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://cosocial.ca/users/timbray/statuses/116432430038225089</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cosocial.ca/users/timbray/statuses/116432430038225089</guid><dc:creator><![CDATA[timbray@cosocial.ca]]></dc:creator><pubDate>Sun, 19 Apr 2026 16:58:10 GMT</pubDate></item><item><title><![CDATA[Reply to My hot take on the vulnpocalypse: on Sun, 19 Apr 2026 16:52:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/sophieschmieg%40infosec.exchange">@<span>sophieschmieg</span></a></span> I'm hoping that we can fix the initial wave of issues and then just have a higher bar for committing new code where we can find or avoid the issues before it's submitted instead of after the fact.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/tess/statuses/116432407521865982</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/tess/statuses/116432407521865982</guid><dc:creator><![CDATA[tess@mastodon.social]]></dc:creator><pubDate>Sun, 19 Apr 2026 16:52:26 GMT</pubDate></item></channel></rss>