Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Today in InfoSec Job Security News:

Today in InfoSec Job Security News:

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
84 Indlæg 64 Posters 18 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    Today in InfoSec Job Security News:

    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

    scy@chaos.socialS This user is from outside of this forum
    scy@chaos.socialS This user is from outside of this forum
    scy@chaos.social
    wrote sidst redigeret af
    #81

    @GossiTheDog But think about the AI-powered "security researchers". They can now use their AI models to find these vulnerabilities and create 8.2 severity issues to fix it again.

    It's like that picture with the circular economy between Nvidia and OpenAI and Microsoft, but with 0days!

    1 Reply Last reply
    0
    • vlkr@social.tchncs.deV vlkr@social.tchncs.de

      @GossiTheDog https://github.com/claude right now showing "Something went wrong, please refresh the page to try again." Yeah, dude.

      crazyeddie@mastodon.socialC This user is from outside of this forum
      crazyeddie@mastodon.socialC This user is from outside of this forum
      crazyeddie@mastodon.social
      wrote sidst redigeret af
      #82

      @vlkr @GossiTheDog I get the same behavior here and can go to other profiles just fine 😛

      No public repos. Something went wrong.

      I guess it could just be that I picked a particularly irrelevant profile to compare against but it did show up just fine without any error.

      Could also be that it's too sudden a shift in interest in that particular user.

      1 Reply Last reply
      0
      • da_667@infosec.exchangeD da_667@infosec.exchange

        @GossiTheDog what's funny to me, is that there were influencers on linkedin a few days ago claiming claudecode could find vulnerabilities in code faster than humans, and they're like "look at all these openssl vulns it found!" now I'm like. "well no shit its finding vulnerabilities, when its the one introducing them."

        zarchasmpgmr@infosec.exchangeZ This user is from outside of this forum
        zarchasmpgmr@infosec.exchangeZ This user is from outside of this forum
        zarchasmpgmr@infosec.exchange
        wrote sidst redigeret af
        #83

        @da_667 @GossiTheDog and I’ve been seeing several posts in the past 48 hours that say that A”I” vuln scanners aren’t finding most of them.

        Almost makes me wonder if there’s a two-pronged attack here. Introduce them and ignore them.

        1 Reply Last reply
        0
        • da_667@infosec.exchangeD da_667@infosec.exchange

          @GossiTheDog ladies and gentlemen, it's this stupid shit (tm) that we are paying up the ass for new SSDs and RAM for.

          zarchasmpgmr@infosec.exchangeZ This user is from outside of this forum
          zarchasmpgmr@infosec.exchangeZ This user is from outside of this forum
          zarchasmpgmr@infosec.exchange
          wrote sidst redigeret af
          #84

          @da_667 @GossiTheDog I have 5 500MB HDDs that are now probably worth thousands.

          1 Reply Last reply
          0
          • pelle@veganism.socialP pelle@veganism.social shared this topic
          Svar
          • Svar som emne
          Login for at svare
          • Ældste til nyeste
          • Nyeste til ældste
          • Most Votes


          • Log ind

          • Har du ikke en konto? Tilmeld

          • Login or register to search.
          Powered by NodeBB Contributors
          Graciously hosted by data.coop
          • First post
            Last post
          0
          • Hjem
          • Seneste
          • Etiketter
          • Populære
          • Verden
          • Bruger
          • Grupper