<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[#Mythos finds a #curl vulnerability]]></title><description><![CDATA[<p><a href="https://mastodon.social/tags/Mythos" rel="tag">#<span>Mythos</span></a> finds a <a href="https://mastodon.social/tags/curl" rel="tag">#<span>curl</span></a> vulnerability</p><p>yes, as in singular one.</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/" title="Mythos finds a curl vulnerability">
<img src="https://daniel.haxx.se/blog/wp-content/uploads/2026/05/jinwon-robot.jpg" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>







<div class="card-body">
<h5 class="card-title">
<a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/">
Mythos finds a curl vulnerability
</a>
</h5>
<p class="card-text line-clamp-3">yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →</p>
</div>
<a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://daniel.haxx.se/blog/wp-content/uploads/2024/07/daniel-greenbg-blackandwhite-413x413-1.jpg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />







<p class="d-inline-block text-truncate mb-0">daniel.haxx.se <span class="text-secondary">(daniel.haxx.se)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/topic/f5fbd5a0-b04c-4d79-9d4c-2f18ae59852e/mythos-finds-a-curl-vulnerability</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 02:42:46 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/f5fbd5a0-b04c-4d79-9d4c-2f18ae59852e.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 11 May 2026 06:02:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Thu, 14 May 2026 17:47:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/das_robin%40defcon.social">@<span>das_robin</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <br />Yes, <a href="https://infosec.exchange/tags/Firefox" rel="tag">#<span>Firefox</span></a> is probably a few orders of magnitude more complex than <a href="https://infosec.exchange/tags/curl" rel="tag">#<span>curl</span></a> and definitely much bigger.</p><p>Still, the blog post explicitly mentions "In addition to fixing the 271 bugs identified by Claude Mythos Preview in the 150 release, we’ve shipped more of these fixes in 149.0.2, 150.0.1, and 150.0.2.", so &gt;270 attributed to <a href="https://infosec.exchange/tags/Mythos" rel="tag">#<span>Mythos</span></a> *alone*.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/oots/statuses/116574182310416125</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/oots/statuses/116574182310416125</guid><dc:creator><![CDATA[oots@infosec.exchange]]></dc:creator><pubDate>Thu, 14 May 2026 17:47:38 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Thu, 14 May 2026 12:32:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> This closely matches the experience Homebrew has also had with Mythos. Also one vulnerability found and in our case it was a pretty irrelevant one.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/mikemcquaid/statuses/116572941578413468</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/mikemcquaid/statuses/116572941578413468</guid><dc:creator><![CDATA[mikemcquaid@mastodon.social]]></dc:creator><pubDate>Thu, 14 May 2026 12:32:05 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 16:44:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> I picked 10 in the poll to play it safe, but 1 was my second choice and I'm not surprised at all. Long live <a href="https://mastodon.social/tags/curl" rel="tag">#<span>curl</span></a> .</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/elgringomexicano/statuses/116556945287416990</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/elgringomexicano/statuses/116556945287416990</guid><dc:creator><![CDATA[elgringomexicano@mastodon.social]]></dc:creator><pubDate>Mon, 11 May 2026 16:44:01 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 16:36:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/das_robin%40defcon.social">@<span>das_robin</span></a></span> <span><a href="/user/oots%40infosec.exchange">@<span>oots</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> there was this blog post dismissing lots of the myth <a href="https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/" rel="nofollow noopener"><span>https://www.</span><span>flyingpenguin.com/the-boy-that</span><span>-cried-mythos-verification-is-collapsing-trust-in-anthropic/</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/uint8_t/statuses/116556917295430754</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/uint8_t/statuses/116556917295430754</guid><dc:creator><![CDATA[uint8_t@chaos.social]]></dc:creator><pubDate>Mon, 11 May 2026 16:36:54 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 13:41:39 GMT]]></title><description><![CDATA[<p><span><a href="https://g.dodies.lv/@normis">@<span>normis</span></a></span> Normi, tu taču zini ka tas ir curl autors?</p>]]></description><link>https://board.circlewithadot.net/post/https://toot.lv/users/peteriskrisjanis/statuses/116556228162652171</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://toot.lv/users/peteriskrisjanis/statuses/116556228162652171</guid><dc:creator><![CDATA[peteriskrisjanis@toot.lv]]></dc:creator><pubDate>Mon, 11 May 2026 13:41:39 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 13:37:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/redsakana%40infosec.exchange">@<span>redsakana</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> </p><p>llm tools found security issues in curl? doubt</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/utf_7/statuses/116556209947335005</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/utf_7/statuses/116556209947335005</guid><dc:creator><![CDATA[utf_7@mastodon.social]]></dc:creator><pubDate>Mon, 11 May 2026 13:37:01 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 13:21:24 GMT]]></title><description><![CDATA[<p><span><a href="https://ibe.social/@totoroot">@<span>totoroot</span></a></span><br />I admit it is very binary.<br /><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodontech.de/users/alterelefant/statuses/116556148539680245</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodontech.de/users/alterelefant/statuses/116556148539680245</guid><dc:creator><![CDATA[alterelefant@mastodontech.de]]></dc:creator><pubDate>Mon, 11 May 2026 13:21:24 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 13:20:02 GMT]]></title><description><![CDATA[<p><a href="/user/alterelefant%40mastodontech.de">@alterelefant@mastodontech.de</a> <a href="/user/bagder%40mastodon.social">@bagder@mastodon.social</a><span> Are you a machine?<br />Classifying finding a single vulnerability (1) as success and 0 as failure sure seems like it </span><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f601.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--grin" style="height:23px;width:auto;vertical-align:middle" title="😁" alt="😁" /><span><br />The world is not black and white and the usefulness of LLMs for finding vulnerabilities IMO isn't either</span></p>]]></description><link>https://board.circlewithadot.net/post/https://ibe.social/notes/am4smnbtuv</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://ibe.social/notes/am4smnbtuv</guid><dc:creator><![CDATA[totoroot@ibe.social]]></dc:creator><pubDate>Mon, 11 May 2026 13:20:02 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 12:59:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> it's all marketing. And any improvements are completely moot, as the actual *costs* to find that single bug were in the tens of thousands of dollars minimum. That's the MINIMUM known cost.<br />It would not surprise me if finding that one bug cost $75k, $100k, $200k of compute time. It's a pile of shit, hilariously inefficient slop that sometimes behaves as a fuzzer that occasionally finds a crumb.</p>]]></description><link>https://board.circlewithadot.net/post/https://weird.autos/users/rootwyrm/statuses/116556063761905885</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://weird.autos/users/rootwyrm/statuses/116556063761905885</guid><dc:creator><![CDATA[rootwyrm@weird.autos]]></dc:creator><pubDate>Mon, 11 May 2026 12:59:50 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 12:40:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f4af.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--100" style="height:23px;width:auto;vertical-align:middle" title="💯" alt="💯" /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/261d.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--point_up" style="height:23px;width:auto;vertical-align:middle" title="☝" alt="☝" />️this</p>]]></description><link>https://board.circlewithadot.net/post/https://toot.lv/users/peteriskrisjanis/statuses/116555988245471887</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://toot.lv/users/peteriskrisjanis/statuses/116555988245471887</guid><dc:creator><![CDATA[peteriskrisjanis@toot.lv]]></dc:creator><pubDate>Mon, 11 May 2026 12:40:38 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 12:30:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/das_robin%40defcon.social">@<span>das_robin</span></a></span> <span><a href="/user/oots%40infosec.exchange">@<span>oots</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> maybe <span><a href="/user/firefoxnightly%40mastodon.social">@<span>firefoxnightly</span></a></span> can comment on that</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/rugk/statuses/116555949657588377</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/rugk/statuses/116555949657588377</guid><dc:creator><![CDATA[rugk@chaos.social]]></dc:creator><pubDate>Mon, 11 May 2026 12:30:49 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 12:26:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/0x0%40hachyderm.io">@<span>0x0</span></a></span> <span><a href="/user/kleisli%40mastodon.social">@<span>kleisli</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> to be clear i picked that number out of my butt, but it is clear to me that it's going to be very hard to make up their investment in it, much less than the min 10x (which would probably be a couple trillion dollars)</p>]]></description><link>https://board.circlewithadot.net/post/https://social.circl.lu/users/quinn/statuses/116555933164174059</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.circl.lu/users/quinn/statuses/116555933164174059</guid><dc:creator><![CDATA[quinn@social.circl.lu]]></dc:creator><pubDate>Mon, 11 May 2026 12:26:38 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 12:24:53 GMT]]></title><description><![CDATA[<p><span><a href="/user/km%40mastodon.babb.no" rel="nofollow noopener">@<span>km</span></a></span> Yeah. I didn’t mean it personally. I wasn’t criticising what you said, I’m sorry if I sounded that way.</p><p>I was just pointing out this constant theme. The only thing that ever is made public is the fully-polished, human-vetted final result. They carefully hide all other details and the press don’t care.</p><p><span><a href="/user/bagder%40mastodon.social" rel="nofollow noopener">@<span>bagder</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/paco/statuses/116555926319010804</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/paco/statuses/116555926319010804</guid><dc:creator><![CDATA[paco@infosec.exchange]]></dc:creator><pubDate>Mon, 11 May 2026 12:24:53 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 12:00:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/4censord%40unfug.social">@<span>4censord</span></a></span> <span><a href="/user/gnirre%40mastodon.social">@<span>gnirre</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> Also, didn't they intentionally disable all mitigations, sandboxing etc. in Firefox *and* include every teeny tiny bug it found (without mentioning the false-positives, which were probably a metric shit ton) to bolster those numbers?</p><p>There were lots of shenanigans afaik.</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/Natanox/statuses/116555829949214805</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/Natanox/statuses/116555829949214805</guid><dc:creator><![CDATA[natanox@chaos.social]]></dc:creator><pubDate>Mon, 11 May 2026 12:00:23 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 11:54:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/paco%40infosec.exchange">@<span>paco</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> yeah, let me clarify: i talked with people who not themselves used mythos, but whose org was given access, so yeah, they just told something which they were told</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.babb.no/users/km/statuses/116555807562697203</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.babb.no/users/km/statuses/116555807562697203</guid><dc:creator><![CDATA[km@mastodon.babb.no]]></dc:creator><pubDate>Mon, 11 May 2026 11:54:41 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 11:49:43 GMT]]></title><description><![CDATA[<p><span><a href="/user/km%40mastodon.babb.no" rel="nofollow noopener">@<span>km</span></a></span> As far as I can tell:</p><ul><li>No one who has worked with raw Mythos output has ever written about it.</li><li>No one who has written about it has ever used it. </li></ul><p>They would much rather have <span><a href="/user/bagder%40mastodon.social" rel="nofollow noopener">@<span>bagder</span></a></span> writing about it because his opinion carries weight. That means he can’t have direct access. To give him access, they’d demand to gag him with an NDA, like everyone else who has access.</p><p>This technique of making readers mentally  fill in the gaps between what is verifiable and what is claimed is genius marketing and really dishonest. But we have come to expect systematic and casual dishonesty from these companies.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/paco/statuses/116555788013542840</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/paco/statuses/116555788013542840</guid><dc:creator><![CDATA[paco@infosec.exchange]]></dc:creator><pubDate>Mon, 11 May 2026 11:49:43 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 11:41:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/gnirre%40mastodon.social" rel="nofollow noopener">@<span>gnirre</span></a></span> <span><a href="/user/bagder%40mastodon.social" rel="nofollow noopener">@<span>bagder</span></a></span> with the most glancing of looks, looking at the 150 version of firefox (and some rounding), <br />curl: 200k lines of c<br />firefox: </p><ul><li>5M lines of rust</li><li>9M lines of C and C++</li><li>200k lines of assembly</li><li>2M lines of python </li></ul><p>so like, without looking at <em>anything</em> else, firefox is <strong>significantly</strong> bigger</p>]]></description><link>https://board.circlewithadot.net/post/https://unfug.social/users/4censord/statuses/116555756066103904</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://unfug.social/users/4censord/statuses/116555756066103904</guid><dc:creator><![CDATA[4censord@unfug.social]]></dc:creator><pubDate>Mon, 11 May 2026 11:41:35 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 11:27:18 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> “On average, every single production source code line of curl has been written (and then rewritten) 4.14 times.”</p><p>curl is the ship of Theseus not once, not twice, but four times <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--smile" style="height:23px;width:auto;vertical-align:middle" title=":D" alt="😄" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/phl/statuses/116555699855439224</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/phl/statuses/116555699855439224</guid><dc:creator><![CDATA[phl@mastodon.social]]></dc:creator><pubDate>Mon, 11 May 2026 11:27:18 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 11:24:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social" rel="nofollow noopener">@<span>bagder</span></a></span> great, so even the Linux Foundation are naming things after the ultimate evil of a famous franchise? (Final Fantasy in this instance.)</p>]]></description><link>https://board.circlewithadot.net/post/https://oldbytes.space/users/eobet/statuses/116555687180817543</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://oldbytes.space/users/eobet/statuses/116555687180817543</guid><dc:creator><![CDATA[eobet@oldbytes.space]]></dc:creator><pubDate>Mon, 11 May 2026 11:24:04 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 11:00:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> This suggests a fun exercise for someone interested in messing around with LLMs:</p><p>1. Put back all the curl security issues previously found by LLM tools by dropping the fix commits from history or otherwise obfuscating the revert.</p><p>2. Feed the re-vulnerabilized repo to a selection of models and see what are the cheapest ones (by memory, time and/or monetary cost) that can find, say, 50%/75%/100% of the issues found by the warehouse-scale "foundation models".</p><p>Feels like a large part of the current results should be doable with significantly smaller resources, because being trained on every tweet and reddit post and libgen book ever is not obviously related to the task.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/redsakana/statuses/116555593459231982</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/redsakana/statuses/116555593459231982</guid><dc:creator><![CDATA[redsakana@infosec.exchange]]></dc:creator><pubDate>Mon, 11 May 2026 11:00:14 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 10:36:13 GMT]]></title><description><![CDATA[<p><span><a href="/user/quinn%40social.circl.lu">@<span>quinn</span></a></span></p><p>Especially if it's subscription-based, as these models seem to be good at finding only specific sets of problems and then dry out, but even 10k per use is really gov or big corpo territory.</p><p><span><a href="/user/kleisli%40mastodon.social">@<span>kleisli</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/0x0/statuses/116555499004319145</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/0x0/statuses/116555499004319145</guid><dc:creator><![CDATA[0x0@hachyderm.io]]></dc:creator><pubDate>Mon, 11 May 2026 10:36:13 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 10:26:47 GMT]]></title><description><![CDATA[<p><span><a href="/user/synlogic4242%40social.vivaldi.net">@<span>synlogic4242</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> Yes, someone really needs to get on to that rewriting thing. Just a pity there hasn't been a weekend in *years* so nobody had the chance!</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/FrankGevaerts/statuses/116555461904753985</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/FrankGevaerts/statuses/116555461904753985</guid><dc:creator><![CDATA[frankgevaerts@mastodon.social]]></dc:creator><pubDate>Mon, 11 May 2026 10:26:47 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 09:36:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/kleisli%40mastodon.social">@<span>kleisli</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <br />if it's something like 10,000 euros a pop, it might not be worth security scans and reviews, except for governmental clients.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.circl.lu/users/quinn/statuses/116555264176803175</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.circl.lu/users/quinn/statuses/116555264176803175</guid><dc:creator><![CDATA[quinn@social.circl.lu]]></dc:creator><pubDate>Mon, 11 May 2026 09:36:30 GMT</pubDate></item><item><title><![CDATA[Reply to #Mythos finds a #curl vulnerability on Mon, 11 May 2026 09:23:33 GMT]]></title><description><![CDATA[<p><span><a href="/user/gnirre%40mastodon.social">@<span>gnirre</span></a></span> I don't know how much they asked or told A about when this was done. It's not "my" access, someone else has the access and ran the analysis</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116555213249142345</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116555213249142345</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Mon, 11 May 2026 09:23:33 GMT</pubDate></item></channel></rss>