<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Important heads-up to FOSS maintainers by Daniel from curl:]]></title><description><![CDATA[<p>Important heads-up to FOSS maintainers by Daniel from curl: </p><p>"Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools."</p><p>Since I'm working for Alpha-Omega currently, please reach out to me if you could use some support regarding this. We're setting up various programs to help FOSS maintainers in the times of "high-quality chaos". </p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/" title="Mythos finds a curl vulnerability">
<img src="https://daniel.haxx.se/blog/wp-content/uploads/2026/05/jinwon-robot.jpg" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>







<div class="card-body">
<h5 class="card-title">
<a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/">
Mythos finds a curl vulnerability
</a>
</h5>
<p class="card-text line-clamp-3">yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →</p>
</div>
<a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://daniel.haxx.se/blog/wp-content/uploads/2024/07/daniel-greenbg-blackandwhite-413x413-1.jpg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />







<p class="d-inline-block text-truncate mb-0">daniel.haxx.se <span class="text-secondary">(daniel.haxx.se)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/topic/de514638-cefe-431f-b0b8-be8870514c43/important-heads-up-to-foss-maintainers-by-daniel-from-curl</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 02:40:56 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/de514638-cefe-431f-b0b8-be8870514c43.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 11 May 2026 09:04:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Important heads-up to FOSS maintainers by Daniel from curl: on Mon, 11 May 2026 13:13:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/mechko%40chaos.social">@<span>mechko</span></a></span> Do you know why it took so long for curl to get access to Mythos? Is there a long line of projects waiting...?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/gnirre/statuses/116556116565991205</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/gnirre/statuses/116556116565991205</guid><dc:creator><![CDATA[gnirre@mastodon.social]]></dc:creator><pubDate>Mon, 11 May 2026 13:13:16 GMT</pubDate></item><item><title><![CDATA[Reply to Important heads-up to FOSS maintainers by Daniel from curl: on Mon, 11 May 2026 10:37:48 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@eliotlear">@<span>eliotlear</span></a></span> <span><a href="/user/mechko%40chaos.social">@<span>mechko</span></a></span> and another good point, the tooling doesn't find new classes of exploits or new approaches to break code.</p><p>Lots of old and familiar kind of holes to go through, still..</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodontti.fi/users/janvenetor/statuses/116555505225375584</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodontti.fi/users/janvenetor/statuses/116555505225375584</guid><dc:creator><![CDATA[janvenetor@mastodontti.fi]]></dc:creator><pubDate>Mon, 11 May 2026 10:37:48 GMT</pubDate></item><item><title><![CDATA[Reply to Important heads-up to FOSS maintainers by Daniel from curl: on Mon, 11 May 2026 10:22:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/mechko%40chaos.social">@<span>mechko</span></a></span> The only thing that's surprising is that it found only one vulnerability.  Curl is a monster of a package with huge numbers of dependencies.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/eliotlear/statuses/116555446818776309</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/eliotlear/statuses/116555446818776309</guid><dc:creator><![CDATA[eliotlear@mastodon.social]]></dc:creator><pubDate>Mon, 11 May 2026 10:22:57 GMT</pubDate></item><item><title><![CDATA[Reply to Important heads-up to FOSS maintainers by Daniel from curl: on Mon, 11 May 2026 10:07:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/mechko%40chaos.social">@<span>mechko</span></a></span> in other words, the cURL codebase is, with apologies to Douglas Adams, “Mostly Bugless”?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/sjaveed/statuses/116555386708971101</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/sjaveed/statuses/116555386708971101</guid><dc:creator><![CDATA[sjaveed@mastodon.social]]></dc:creator><pubDate>Mon, 11 May 2026 10:07:39 GMT</pubDate></item><item><title><![CDATA[Reply to Important heads-up to FOSS maintainers by Daniel from curl: on Mon, 11 May 2026 09:25:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/mechko%40chaos.social">@<span>mechko</span></a></span><br /><span><a href="/user/purpleidea%40mastodon.social">@<span>purpleidea</span></a></span> FYI <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f446.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--point_up_2" style="height:23px;width:auto;vertical-align:middle" title="👆" alt="👆" /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f3fc.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--skin-tone-3" style="height:23px;width:auto;vertical-align:middle" title="🏼" alt="🏼" /></p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/ringods/statuses/116555222650670473</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/ringods/statuses/116555222650670473</guid><dc:creator><![CDATA[ringods@hachyderm.io]]></dc:creator><pubDate>Mon, 11 May 2026 09:25:56 GMT</pubDate></item><item><title><![CDATA[Reply to Important heads-up to FOSS maintainers by Daniel from curl: on Mon, 11 May 2026 09:09:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/mechko%40chaos.social" rel="ugc">@<span>mechko</span></a></span> Is any open source project in scope? If I maintain an open source project, can I just ask you to run it against my project?</p>]]></description><link>https://board.circlewithadot.net/post/https://ap.nil.im/objects/21d98c58-e044-4750-b841-0621031ce4e5</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://ap.nil.im/objects/21d98c58-e044-4750-b841-0621031ce4e5</guid><dc:creator><![CDATA[js@ap.nil.im]]></dc:creator><pubDate>Mon, 11 May 2026 09:09:19 GMT</pubDate></item></channel></rss>