Exploits (1 blogmarks)

← Blogmarks

Just a rumour of a bug is enough to find a security exploit these days

https://anil.recoil.org/notes/rumour-is-the-exploit

If it took me just a minute to create my own exploit locally, then ten minutes actually seems quite long for an automated attack window to start! A determined attacker who is monitoring package repositories could easily be exploiting them within seconds.

We’ve already entered an era where we need to completely rethink the process of reporting and patching security issues.

LLMs are merrily generating exploits, but our ability to defend against them isn't necessarily improving as maintainer validation, triage and release rates stay flat.