<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?]]></title><description><![CDATA[<p>When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?</p><p>Well, here they are. We are unhiding 12 security bugs that are representative of the issues we have found.</p><p><a href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/" rel="nofollow noopener"><span>https://</span><span>hacks.mozilla.org/2026/05/behi</span><span>nd-the-scenes-hardening-firefox/</span></a>.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://cdn.masto.host/socialsecurityplumbing/media_attachments/files/116/534/183/553/883/099/original/dfa5b28ddf139af7.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/dcdfc12d-bf08-4117-8495-9424f37f52c4/when-we-said-that-we-found-and-fixed-hundreds-of-bugs-in-firefox-using-ai-people-were-skeptical-and-said-where-are-the-bugs</link><generator>RSS for Node</generator><lastBuildDate>Fri, 05 Jun 2026 05:43:57 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/dcdfc12d-bf08-4117-8495-9424f37f52c4.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 07 May 2026 16:15:27 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Fri, 08 May 2026 04:01:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/freddy%40social.security.plumbing">@<span>freddy</span></a></span> Curious exactly how many critical/high <a href="https://disobey.net/tags/Firefox" rel="tag">#<span>Firefox</span></a> bugs were reported by <a href="https://disobey.net/tags/Mythos" rel="tag">#<span>Mythos</span></a>, vs how many were confirmed/accepted as such by your team?</p>]]></description><link>https://board.circlewithadot.net/post/https://disobey.net/users/endareth/statuses/116536958099458035</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://disobey.net/users/endareth/statuses/116536958099458035</guid><dc:creator><![CDATA[endareth@disobey.net]]></dc:creator><pubDate>Fri, 08 May 2026 04:01:01 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 23:34:22 GMT]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://social.security.plumbing/@freddy/116534213887768480" rel="nofollow noopener"><span>https://</span><span>social.security.plumbing/@fred</span><span>dy/116534213887768480</span></a></p><p><span><a href="https://mk.absturztau.be/@enigmatico">@<span>enigmatico</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116535909549287345</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116535909549287345</guid><dc:creator><![CDATA[freddy@social.security.plumbing]]></dc:creator><pubDate>Thu, 07 May 2026 23:34:22 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 22:16:02 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@skryking">@<span>skryking</span></a></span> <span><a href="/user/alesandroortiz%40infosec.exchange">@<span>AlesandroOrtiz</span></a></span> less valid from bug bounty, given we found them first? <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /> might change over time of course</p>]]></description><link>https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116535601576242879</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116535601576242879</guid><dc:creator><![CDATA[freddy@social.security.plumbing]]></dc:creator><pubDate>Thu, 07 May 2026 22:16:02 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 20:13:15 GMT]]></title><description><![CDATA[<p><span><a href="/user/alesandroortiz%40infosec.exchange">@<span>AlesandroOrtiz</span></a></span> <span><a href="/user/freddy%40social.security.plumbing">@<span>freddy</span></a></span> I would expect to see a really big surge initially and then tail off unless there's some big step forward in tooling, be it LLM/ML related or other...then tail off again after each initial burst.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/skryking/statuses/116535118778423181</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/skryking/statuses/116535118778423181</guid><dc:creator><![CDATA[skryking@infosec.exchange]]></dc:creator><pubDate>Thu, 07 May 2026 20:13:15 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 19:29:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/freddy%40social.security.plumbing">@<span>freddy</span></a></span> Less? That's very surprising.</p><p>Thought it would continue increasing despite *gestures wildly* everything.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116534948032473870</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116534948032473870</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Thu, 07 May 2026 19:29:50 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 19:25:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/alesandroortiz%40infosec.exchange">@<span>AlesandroOrtiz</span></a></span> yeah, we will see how things go. Due to *gestures wildly* recent events, we also had a bit less submissions, so… <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title="🤷" alt="🤷" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--male_sign" style="height:23px;width:auto;vertical-align:middle" title="♂" alt="♂" />️</p>]]></description><link>https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116534929281919643</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116534929281919643</guid><dc:creator><![CDATA[freddy@social.security.plumbing]]></dc:creator><pubDate>Thu, 07 May 2026 19:25:04 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 19:16:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/freddy%40social.security.plumbing">@<span>freddy</span></a></span> Ah, forgot about those changes. (It's been a _very long_ 2 months.)</p><p>Reward amounts seem unchanged and Firefox still pays for reasonable moderate impact vulns, which is appreciated.</p><p>Hope reward amounts aren't lowered given the new landscape, especially since FF rewards were much lower than other browser VRPs (now about the same).</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116534893776448499</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116534893776448499</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Thu, 07 May 2026 19:16:02 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 18:58:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/alesandroortiz%40infosec.exchange">@<span>AlesandroOrtiz</span></a></span> <a href="https://attackanddefense.dev/2026/03/13/bug-bounty-program-updates-2026.html" rel="nofollow noopener"><span>https://</span><span>attackanddefense.dev/2026/03/1</span><span>3/bug-bounty-program-updates-2026.html</span></a> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116534823177744944</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116534823177744944</guid><dc:creator><![CDATA[freddy@social.security.plumbing]]></dc:creator><pubDate>Thu, 07 May 2026 18:58:05 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 18:44:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/freddy%40social.security.plumbing">@<span>freddy</span></a></span> Thanks for sharing and making those reports public early. Great insight into what's happening with browser VRPs.</p><p>Is Mozilla planning changes to the Firefox VRP in response to this, similar to recent changes to the Chrome VRP?</p><p>(Or have changes already been made? I'm not closely following the Firefox VRP, unfortunately.)</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116534769807845206</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116534769807845206</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Thu, 07 May 2026 18:44:30 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 18:16:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/yoasif%40mastodon.social">@<span>yoasif</span></a></span> <span><a href="/user/henearxn%40chaos.social">@<span>HeNeArXn</span></a></span> Yeah, I don't think we can share the tools but happy to answer questions <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116534661550434830</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116534661550434830</guid><dc:creator><![CDATA[freddy@social.security.plumbing]]></dc:creator><pubDate>Thu, 07 May 2026 18:16:59 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 17:18:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/freddy%40social.security.plumbing">@<span>freddy</span></a></span> <span><a href="/user/henearxn%40chaos.social">@<span>HeNeArXn</span></a></span> The attachments show the result, not the process. People using the tools would be able to give us a better understanding of what is actually happening.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/yoasif/statuses/116534432230427672</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/yoasif/statuses/116534432230427672</guid><dc:creator><![CDATA[yoasif@mastodon.social]]></dc:creator><pubDate>Thu, 07 May 2026 17:18:39 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 17:15:18 GMT]]></title><description><![CDATA[<p><span><a href="/user/yoasif%40mastodon.social">@<span>yoasif</span></a></span> <span><a href="/user/henearxn%40chaos.social">@<span>HeNeArXn</span></a></span> You can just click the bugs and see the attachments? <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116534419004059508</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116534419004059508</guid><dc:creator><![CDATA[freddy@social.security.plumbing]]></dc:creator><pubDate>Thu, 07 May 2026 17:15:18 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 17:11:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/henearxn%40chaos.social">@<span>HeNeArXn</span></a></span> <span><a href="/user/freddy%40social.security.plumbing">@<span>freddy</span></a></span> Touché! I understood that "using" AI gave you the result - the topline here does the same "found and fixed".</p><p>We know the Firefox team didn't find the bugs themselves - that was AI - and the initial post implied (to me) an equivalency between finding and fixing.</p><p>I hoped to understand how much the AI had contributed to fixing the bugs, but it seems like we'll have to see another blog post for that. </p><p>Basically, what does "using AI" mean when fixing these bugs.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/yoasif/statuses/116534403061940222</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/yoasif/statuses/116534403061940222</guid><dc:creator><![CDATA[yoasif@mastodon.social]]></dc:creator><pubDate>Thu, 07 May 2026 17:11:14 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 16:32:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/yoasif%40mastodon.social">@<span>yoasif</span></a></span> <span><a href="/user/freddy%40social.security.plumbing">@<span>freddy</span></a></span> the original post says "using", not "by"?</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/HeNeArXn/statuses/116534249005735653</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/HeNeArXn/statuses/116534249005735653</guid><dc:creator><![CDATA[henearxn@chaos.social]]></dc:creator><pubDate>Thu, 07 May 2026 16:32:04 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 16:26:13 GMT]]></title><description><![CDATA[<p><span><a href="/user/freddy%40social.security.plumbing">@<span>freddy</span></a></span> You are the ones fixing the bugs, but your comment is pretty ambiguous -- your initial post says the bugs were fixed by AI, and then you say that you need a human author to write and review  the patch.</p><p>Which is it - is it a human author or an AI author? </p><p>If it is a human author, can you really say that it was fixed by AI?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/yoasif/statuses/116534226040725586</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/yoasif/statuses/116534226040725586</guid><dc:creator><![CDATA[yoasif@mastodon.social]]></dc:creator><pubDate>Thu, 07 May 2026 16:26:13 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 16:23:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/yoasif%40mastodon.social">@<span>yoasif</span></a></span> You'll see attachments in some of the bugs. We asked the LLM to propose a patch, but it was real people who were assigned to the bug and they were of course free to pick a different approach. </p><p>As with all patches in Firefox, we need a human author and another human to review the patch. <a href="https://firefox-source-docs.mozilla.org/contributing/ai-coding.html" rel="nofollow noopener"><span>https://</span><span>firefox-source-docs.mozilla.or</span><span>g/contributing/ai-coding.html</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116534213887768480</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.security.plumbing/users/freddy/statuses/116534213887768480</guid><dc:creator><![CDATA[freddy@social.security.plumbing]]></dc:creator><pubDate>Thu, 07 May 2026 16:23:08 GMT</pubDate></item><item><title><![CDATA[Reply to When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? on Thu, 07 May 2026 16:20:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/freddy%40social.security.plumbing">@<span>freddy</span></a></span> You fixed the bugs with AI too?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/yoasif/statuses/116534204026398149</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/yoasif/statuses/116534204026398149</guid><dc:creator><![CDATA[yoasif@mastodon.social]]></dc:creator><pubDate>Thu, 07 May 2026 16:20:37 GMT</pubDate></item></channel></rss>