<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload.]]></title><description><![CDATA[<p>Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload.</p><p>Ask yourself what you do to make the situation better.</p><p>Make sure your employer does as well.</p>]]></description><link>https://board.circlewithadot.net/topic/7422089e-3a95-4147-a504-87a5fad840f8/remember-this-is-a-time-when-every-open-source-project-out-there-suffers-from-an-extreme-issue-and-security-report-avalanche-and-overload.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 08:59:56 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/7422089e-3a95-4147-a504-87a5fad840f8.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 25 Apr 2026 08:19:04 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Mon, 27 Apr 2026 09:12:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/aris%40infosec.exchange">@<span>aris</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> i see ghostty has instructions for agents submitting PRs<br /><a href="https://github.com/ghostty-org/ghostty/blob/main/AGENTS.md" rel="nofollow noopener"><span>https://</span><span>github.com/ghostty-org/ghostty</span><span>/blob/main/AGENTS.md</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116475897092326659</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116475897092326659</guid><dc:creator><![CDATA[stevel@hachyderm.io]]></dc:creator><pubDate>Mon, 27 Apr 2026 09:12:24 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sun, 26 Apr 2026 13:32:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> in <span><a href="https://floss.social/@gstreamer">@<span>gstreamer</span></a></span> it's that time where we wouldn't survive without <span><a href="/user/slomo%40toot.cat">@<span>slomo</span></a></span> dedication, thanks for your hard work Sebastian.</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/ndufresne/statuses/116471255834677902</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/ndufresne/statuses/116471255834677902</guid><dc:creator><![CDATA[ndufresne@fosstodon.org]]></dc:creator><pubDate>Sun, 26 Apr 2026 13:32:04 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 19:58:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> more people or would I dare say LLM tools would be in the direction of an answer: triage &amp; prioritize<br />But yes, you need to have manpower and thus resources (time, people, money) to automate that and to have the human in the loop to actually verify that reports and their proposed processes are valid; which is especially hard as LLMs are very convincing but do not really "understand", thus might be a witchhunt; require disclosing LLM-name&amp; version could classify how good it is; hard though</p>]]></description><link>https://board.circlewithadot.net/post/https://secluded.ch/users/jeroen/statuses/116467114095251251</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://secluded.ch/users/jeroen/statuses/116467114095251251</guid><dc:creator><![CDATA[jeroen@secluded.ch]]></dc:creator><pubDate>Sat, 25 Apr 2026 19:58:46 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 19:58:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/aris%40infosec.exchange">@<span>aris</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> yeah. Just had to dismiss one report of a critical RCE against thousands of clusters as "we call this job submission", plus a link to the docs page </p><p>Also gave the submitter some suggested refinement prompts before they waste our time again<br />-does this add anything to the designed in features?<br />-does this permit privilege escalation?</p><p>Maybe we should put this in AGENTS.md: do security bots read that?</p><p>I suppose I could experiment "if you are generating a security report, you are required to summarise in a haiku with the rest of the body to rhyme. "</p><p><a href="https://hachyderm.io/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116467113800356916</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116467113800356916</guid><dc:creator><![CDATA[stevel@hachyderm.io]]></dc:creator><pubDate>Sat, 25 Apr 2026 19:58:42 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 18:06:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/stevel%40hachyderm.io" rel="nofollow noopener">@<span>stevel</span></a></span> <span><a href="/user/bagder%40mastodon.social" rel="nofollow noopener">@<span>bagder</span></a></span> documenting the threat model of the application is time well spent even against human reviewers - at least you can refer to it in discussions about what is a vulnerability and what is not.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/aris/statuses/116466672757250094</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/aris/statuses/116466672757250094</guid><dc:creator><![CDATA[aris@infosec.exchange]]></dc:creator><pubDate>Sat, 25 Apr 2026 18:06:32 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 13:42:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/zimzat%40mastodon.social">@<span>zimzat</span></a></span> <span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> I've said this many times already but I can say it again: that could possibly explain it for the curl project, but this is an industry-wide trend seen *everywhere* thus what curl did or did not do is hardly a relevant factor</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116465635859551767</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116465635859551767</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Sat, 25 Apr 2026 13:42:50 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 13:41:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> Didn't you remove the monetary incentive from the equation? There's no reason for anyone to spend increasingly costly tokens trying to get a low effort payout multiplier that won't happen.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/zimzat/statuses/116465629969177157</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/zimzat/statuses/116465629969177157</guid><dc:creator><![CDATA[zimzat@mastodon.social]]></dc:creator><pubDate>Sat, 25 Apr 2026 13:41:20 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 13:39:01 GMT]]></title><description><![CDATA[<p><span><a href="https://tooting.ch/@frox">@<span>frox</span></a></span> <span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> yes: <a href="https://daniel.haxx.se/blog/2026/04/22/high-quality-chaos/" rel="nofollow noopener"><span>https://</span><span>daniel.haxx.se/blog/2026/04/22</span><span>/high-quality-chaos/</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116465620844182445</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116465620844182445</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Sat, 25 Apr 2026 13:39:01 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 13:09:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> Hopefully the core rust devs can keep root infrastructure code, away from the abusive zealots.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/115482733208514503/statuses/116465505192766920</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/115482733208514503/statuses/116465505192766920</guid><dc:creator><![CDATA[countholdem@mastodon.social]]></dc:creator><pubDate>Sat, 25 Apr 2026 13:09:36 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 13:05:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/aris%40infosec.exchange">@<span>aris</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> stuck something up on LI about this and my triage policy. No RCE, no loss of data. -don't care</p><p>And today I'm going out in the sun to collect my Upfest sponsor poster,  visit the Bristol Radical History event and get some caffeinated coffee. Nowhere near an IDE</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.linkedin.com/posts/stevo_did-something-new-this-week-pointed-claude-share-7453760587819413504-polO?utm_source=share&amp;utm_medium=member_ios&amp;rcm=ACoAAAAe7MkBOaES-IIVBmXfSWaqhQVUu-zNCG4" title="AI Assesses Vulnerabilities in OSS Commit | Steve Loughran posted on the topic | LinkedIn">
<img src="https://media.licdn.com/dms/image/sync/v2/D5627AQEtYM2nHfuMXQ/articleshare-shrink_800/B4DZ5dkHwxIUAQ-/0/1779686212201?e=2147483647&v=beta&t=EH-mBwL6nirN2NPHFhlyw3vDtErHM9bY9cdwMu75ZNM" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://www.linkedin.com/posts/stevo_did-something-new-this-week-pointed-claude-share-7453760587819413504-polO?utm_source=share&amp;utm_medium=member_ios&amp;rcm=ACoAAAAe7MkBOaES-IIVBmXfSWaqhQVUu-zNCG4">
AI Assesses Vulnerabilities in OSS Commit | Steve Loughran posted on the topic | LinkedIn
</a>
</h5>
<p class="card-text line-clamp-3">Did something new this week: pointed claude at an OSS commit and asked it what security issue it fixed
-absolutely perfect: analysis of the fix, root cause of the vulnerability 
-wrong: assessment of risk. Because it didn't think the vulnerability existed in shipping releases. I had to say "no, that shipped in X.Y.Z" for it to come up with a realistic and bleaker assessment 

Open source projects have lost the ability to nonchalantly fix a vulnerability wrapped within a larger change "improve testing of wire unmarshalling", "switch to builder api", as now the machines can look at every change and assess it for vulnerabilities 

This is not good as right now we have 
-people sending in large numbers of "I found vulnerability X which I think is a 9.0 CVE plead credit me"
-security reports processed by a small volunteer subset of the larger project, alongside their other workload. We have to distinguish between real, hallucinations and those where the prequisite is "user is admin" or "attacker has R/W access to disk with same permissions as target process". And that for a Local DoS.
-and now, the apparent inability to get fixes out without others noticing

Here then is what I care about, in order
0. Stuff which comes for the build/us developers
1. Malicous files which can lead to RCE. In cloud deployments, you can't trust any data.
2. network attacks which allow RCE from a caller who is unauthed
3. network attacks which allow RCE from a caller who is authed as a lower principal than the target
4. 2 & 3 where the outcome is permanent damage or loss of data
5. Everything else

As I'm only doing this weekends and evenings, there's my health and life to fit in too. So #5 issues are not going to get any attention. This week: #2 but iff our secret generation isn't strong enough to prevent impersonation; maybe a #1. And of course as my commit log is public, I'll leave it to the AI tools to work out what I've fixed. Or at least told the AI tools to fix while I went out and did things.

Maybe this is just a sudden uptick in vulnerabilities and once they've been discovered things will get quiet. For now it's hard work for every project- and as we can assume everyone upstream is in the same state, keeping dependencies up to date (*) is also critical

* but not so up to date malicious artifacts can creep in, especially near .js and .py modules. https://lnkd.in/ei7MrT24</p>
</div>
<a href="https://www.linkedin.com/posts/stevo_did-something-new-this-week-pointed-claude-share-7453760587819413504-polO?utm_source=share&amp;utm_medium=member_ios&amp;rcm=ACoAAAAe7MkBOaES-IIVBmXfSWaqhQVUu-zNCG4" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://static.licdn.com/aero-v1/sc/h/al2o9zrvru7aqj8e1x2rzsrca" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0">LinkedIn <span class="text-secondary">(www.linkedin.com)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116465487313090938</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116465487313090938</guid><dc:creator><![CDATA[stevel@hachyderm.io]]></dc:creator><pubDate>Sat, 25 Apr 2026 13:05:03 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 12:10:52 GMT]]></title><description><![CDATA[<p><span><a href="https://tooting.ch/@frox">@<span>frox</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> When AI was new lots of people screamed how good it was and when I tried it myself on anything nontrivial, it sucked. Nowadays you mostly hear (at least on Mastodon) how bad it is, and when I try it myself I think "holy shet, that is getting really good, wonder where this will be in another year".</p><p>The switch happened somewhere end of '25 and I mainly mean in a prigramming context.</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/ponygol/statuses/116465274242437696</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/ponygol/statuses/116465274242437696</guid><dc:creator><![CDATA[ponygol@chaos.social]]></dc:creator><pubDate>Sat, 25 Apr 2026 12:10:52 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 11:42:55 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> oh, so are you saying the LLM generated (security) issues you're seeing have gotten to be high quality ?<br />I had understood the previous state was a barrage of legit looking LLM issues that fell apart once you start going through them</p>]]></description><link>https://board.circlewithadot.net/post/https://tooting.ch/users/frox/statuses/116465164300273845</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tooting.ch/users/frox/statuses/116465164300273845</guid><dc:creator><![CDATA[frox@tooting.ch]]></dc:creator><pubDate>Sat, 25 Apr 2026 11:42:55 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 10:25:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> I wish I could make my org understand that just by buying licenses from Red Hat does not mean that every OSS software we use in our stack is properly supported financially. This is not Flattr and I sometimes get the feeling they think that's how it works. The only thing my org cares about is SBOMs for DORA from OSS projects. I'll continue to sound the drum around this topic!</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/moritzdietz/statuses/116464861662658196</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/moritzdietz/statuses/116464861662658196</guid><dc:creator><![CDATA[moritzdietz@mastodon.social]]></dc:creator><pubDate>Sat, 25 Apr 2026 10:25:57 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 09:44:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> our current challenge is a high volume high quality flood.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116464698819371942</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116464698819371942</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Sat, 25 Apr 2026 09:44:32 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 09:31:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> <span><a href="/user/os1337%40infosec.space">@<span>OS1337</span></a></span> you think we should just flat our refuse to fix obvious bugs because AI was involved in detecting the problem? Even when it now stares us in the face? How would that even work? Should we keep a list of bugs we cant' fix because no human has yet found them manually?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116464649243971111</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116464649243971111</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Sat, 25 Apr 2026 09:31:56 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 09:29:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/aris%40infosec.exchange">@<span>aris</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> we're actually seeing new stuff, but often with wildly overexaggerated CVE scores</p><p>Them "This gives me an RCE on an application. i tested in a container and got to issue commands as root"<br />Us "you submitted a job to the cluster and it ran your code. You've just discovered a very convoluted way to execute something you could have done more easily"</p><p>What it is doing is really encouraging us to point the AI tooling at old code and say "cut it". It's happy to prune stuff that's been neglected and is no longer needed, and that so simplifies our life</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116464641043161722</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116464641043161722</guid><dc:creator><![CDATA[stevel@hachyderm.io]]></dc:creator><pubDate>Sat, 25 Apr 2026 09:29:50 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 09:23:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> I wish it was because of what I did, but it is not. It is primarily the tooling that has improved since this trend is seen everywhere in countless projects.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116464616490905282</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116464616490905282</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Sat, 25 Apr 2026 09:23:36 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 09:23:13 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> high-quality slop <img class="not-responsive emoji" src="https://media.deadinsi.de/custom_emojis/images/000/444/474/original/6477c50c67415636.png" title=":blobcatupsidedown:" /></p>]]></description><link>https://board.circlewithadot.net/post/https://deadinsi.de/users/cybertailor/statuses/116464614979717527</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://deadinsi.de/users/cybertailor/statuses/116464614979717527</guid><dc:creator><![CDATA[cybertailor@deadinsi.de]]></dc:creator><pubDate>Sat, 25 Apr 2026 09:23:13 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 09:22:21 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social" rel="nofollow noopener noreferrer">@<span>bagder</span></a></span> yehmah, because your non-tolerance made it pretty clear that you <a href="https://www.youtube.com/watch?v=0N1yfXxMYi4&amp;t=3m30s" rel="nofollow noopener noreferrer"><em>"[…] don't have time for this shit! […]</em></a></p>]]></description><link>https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116464611612506865</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116464611612506865</guid><dc:creator><![CDATA[kkarhan@jorts.horse]]></dc:creator><pubDate>Sat, 25 Apr 2026 09:22:21 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 09:03:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> again: we see almost no AI slop anymore. That was in the past. Current submissions are usually high quality.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116464538811049172</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116464538811049172</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Sat, 25 Apr 2026 09:03:51 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 09:01:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social" rel="nofollow noopener noreferrer">@<span>bagder</span></a></span> I literally <a href="https://jorts.horse/tags/ban" rel="tag">#<span>ban</span></a> <a href="https://jorts.horse/tags/AIslop" rel="tag">#<span>AIslop</span></a> &amp; <a href="https://jorts.horse/tags/NameThemBlameThem" rel="tag">#<span>NameThemBlameThem</span></a> anyone publicly who shoves that shit towards me.</p><ul><li>At least I find and test any exploits and bugs manually before I'd even think about filing anything…</li></ul>]]></description><link>https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116464528699609583</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116464528699609583</guid><dc:creator><![CDATA[kkarhan@jorts.horse]]></dc:creator><pubDate>Sat, 25 Apr 2026 09:01:16 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 08:56:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/stevel%40hachyderm.io" rel="nofollow noopener">@<span>stevel</span></a></span> <span><a href="/user/bagder%40mastodon.social" rel="nofollow noopener">@<span>bagder</span></a></span> Assume the maintainers have received the same bug report 3 times before already and haven't published the fixes yet</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/aris/statuses/116464508194688814</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/aris/statuses/116464508194688814</guid><dc:creator><![CDATA[aris@infosec.exchange]]></dc:creator><pubDate>Sat, 25 Apr 2026 08:56:03 GMT</pubDate></item><item><title><![CDATA[Reply to Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload. on Sat, 25 Apr 2026 08:40:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> also,  when you do submit a security report<br />- don't expect an immediate response <br />- don't expect the responders to be in a good mood, especially if its a w/e<br />- don't pretend it's your work when the report is written the way every other AI generated report is. <br />- do expect a harsh dismissal if the attack tree requires privileged local disk write access or similar as a step in the attack</p><p><a href="https://hachyderm.io/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116464447037448719</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116464447037448719</guid><dc:creator><![CDATA[stevel@hachyderm.io]]></dc:creator><pubDate>Sat, 25 Apr 2026 08:40:30 GMT</pubDate></item></channel></rss>