<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues]]></title><description><![CDATA[<p>is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues</p>]]></description><link>https://board.circlewithadot.net/topic/a403eef4-93c9-4ff7-810d-e2aef6aa5ca0/is-it-just-me-or-does-the-a.-i.-companies-recent-focus-on-automating-exploit-finding-read-as-an-engage-with-us-or-else-ploy-against-the-projects-that-wouldn-t-take-generated-code-contributions-but-can-t-ignore-security-issues</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 09:45:04 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/a403eef4-93c9-4ff7-810d-e2aef6aa5ca0.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 08 Apr 2026 01:43:49 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 13:30:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/pozorvlak%40mathstodon.xyz">@<span>pozorvlak</span></a></span> <span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span></p><p>to be clear, if you believe openbsd has a lower defect rather than any other of the bsds, you're absolutely being taken for a ride</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116369327887022736</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116369327887022736</guid><dc:creator><![CDATA[tef@mastodon.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 13:30:27 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 13:27:29 GMT]]></title><description><![CDATA[<p><span><a href="/user/pozorvlak%40mathstodon.xyz">@<span>pozorvlak</span></a></span> <span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> alas, "secure programing in C" turns out to be more than just yelling at linux developers</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116369316221368430</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116369316221368430</guid><dc:creator><![CDATA[tef@mastodon.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 13:27:29 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 09:24:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/tef%40mastodon.social">@<span>tef</span></a></span> <span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> sure, but *every* new analysis technique finds a whole bunch of bugs at first and then levels off after a while. That said, I'm genuinely impressed at some of the things they've found - a 27yo 0day in OpenBSD? Wild.</p>]]></description><link>https://board.circlewithadot.net/post/https://mathstodon.xyz/users/pozorvlak/statuses/116368359410235514</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mathstodon.xyz/users/pozorvlak/statuses/116368359410235514</guid><dc:creator><![CDATA[pozorvlak@mathstodon.xyz]]></dc:creator><pubDate>Wed, 08 Apr 2026 09:24:09 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 03:40:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> it’s finding real issues. Anything that finds real issues and costs money will feel like an “engage with us Or Else” situation</p>]]></description><link>https://board.circlewithadot.net/post/https://tech.lgbt/users/fay59/statuses/116367009845189820</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tech.lgbt/users/fay59/statuses/116367009845189820</guid><dc:creator><![CDATA[fay59@tech.lgbt]]></dc:creator><pubDate>Wed, 08 Apr 2026 03:40:57 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 03:12:21 GMT]]></title><description><![CDATA[<p><span><a href="/user/tef%40mastodon.social">@<span>tef</span></a></span> <span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> Which is: not fully true! Defenders get to define the territory, including audit and observability. Finding a vuln, developing an exploit — way too easy. Making it operational and maintaining the capability over time: somewhat to substantially more fraught. (Still way, way too easy, of course)</p>]]></description><link>https://board.circlewithadot.net/post/https://wandering.shop/users/fugueish/statuses/116366897394267665</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://wandering.shop/users/fugueish/statuses/116366897394267665</guid><dc:creator><![CDATA[fugueish@wandering.shop]]></dc:creator><pubDate>Wed, 08 Apr 2026 03:12:21 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 03:09:33 GMT]]></title><description><![CDATA[<p><span><a href="/user/fugueish%40wandering.shop">@<span>fugueish</span></a></span> <span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> alas "they only have to get lucky once, we have to get lucky every time" is as true as it ever was</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116366886430804233</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116366886430804233</guid><dc:creator><![CDATA[tef@mastodon.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 03:09:33 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 02:30:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/tef%40mastodon.social">@<span>tef</span></a></span> <span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> I get you, and it's a reasonable note! But also, fuzzers do keep working (and we keep getting surprised all over again when someone makes a fuzzer that can reach a previously unreachable area).</p>]]></description><link>https://board.circlewithadot.net/post/https://wandering.shop/users/fugueish/statuses/116366733176186554</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://wandering.shop/users/fugueish/statuses/116366733176186554</guid><dc:creator><![CDATA[fugueish@wandering.shop]]></dc:creator><pubDate>Wed, 08 Apr 2026 02:30:35 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 02:19:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> <a href="https://gist.github.com/sayrer/659bd4098045164ad9a003df449b6a81" rel="nofollow noopener"><span>https://</span><span>gist.github.com/sayrer/659bd40</span><span>98045164ad9a003df449b6a81</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/sayrer/statuses/116366689964326987</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/sayrer/statuses/116366689964326987</guid><dc:creator><![CDATA[sayrer@mastodon.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 02:19:36 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 02:18:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/fugueish%40wandering.shop">@<span>fugueish</span></a></span> <span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> i'm not saying "it doesn't work" but "beware the low hanging fruit giving you false estimates about success rate"</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116366687008714495</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116366687008714495</guid><dc:creator><![CDATA[tef@mastodon.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 02:18:50 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 02:16:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/fugueish%40wandering.shop">@<span>fugueish</span></a></span> <span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> this was true of fuzzing before but i admit it is far more subsidized now</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116366677930116198</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116366677930116198</guid><dc:creator><![CDATA[tef@mastodon.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 02:16:32 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 02:01:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/joe%40f.duriansoftware.com" rel="nofollow noopener noreferrer">@<span>joe</span></a></span> the "we found a local privesc in Linux" seemed particularly silly to tout... we have local privesc in Linux at home</p>]]></description><link>https://board.circlewithadot.net/post/https://jorts.horse/users/migratory/statuses/116366618586154227</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://jorts.horse/users/migratory/statuses/116366618586154227</guid><dc:creator><![CDATA[migratory@jorts.horse]]></dc:creator><pubDate>Wed, 08 Apr 2026 02:01:26 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 02:00:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> it absolutely comes across as a protection racket</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/aburka/statuses/116366616089311661</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/aburka/statuses/116366616089311661</guid><dc:creator><![CDATA[aburka@hachyderm.io]]></dc:creator><pubDate>Wed, 08 Apr 2026 02:00:48 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 02:00:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/tef%40mastodon.social">@<span>tef</span></a></span> <span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> They seem to avoid talking about solid defensive remedies (some of which LLMs likely will also be able to do well, such as translation and theorem proving — there are already results), for some reason. Until that strong medicine is applied, I think they'll continue producing new bugs and new kinds of bugs. Underestimating them is unwise for defenders. Keep in mind also they are military contractors.</p>]]></description><link>https://board.circlewithadot.net/post/https://wandering.shop/users/fugueish/statuses/116366614656808896</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://wandering.shop/users/fugueish/statuses/116366614656808896</guid><dc:creator><![CDATA[fugueish@wandering.shop]]></dc:creator><pubDate>Wed, 08 Apr 2026 02:00:26 GMT</pubDate></item><item><title><![CDATA[Reply to is it just me, or does the a. i. companies’ recent focus on automating exploit finding read as an “engage with us Or Else” ploy against the projects that wouldn’t take generated code contributions but can’t ignore security issues on Wed, 08 Apr 2026 01:47:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/joe%40f.duriansoftware.com">@<span>joe</span></a></span> it's more "this is actually a thing it can do" i feel as fuzzing does produce results</p><p>but, well, after the burst of low hanging fruit, i don't expect a regular crop of bugs</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116366563036941307</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/tef/statuses/116366563036941307</guid><dc:creator><![CDATA[tef@mastodon.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 01:47:19 GMT</pubDate></item></channel></rss>