you are viewing a single comment's thread
view the rest of the comments
[–] 109 points 1 month ago (3 children)

A separate vulnerability in Linux allows users with limited rights to escalate to root. Tracked as CVE-2026-43499, it lurked in the OS for 15 years. Researchers from Nebula Security said they discovered it using Vega, Nebula’s AI-assisted vulnerability scanner. Matt Lucas, a researcher and founder of RedEye Security, explained

This will become more and more common as we use AI to find vulnerabilities faster (hopefully) than bad actors can use AI to find vulnerabilities.

  • source
  • hideshow 6 child comments
  • [–] 88 points 1 month ago (3 children)

    If you pay attention you can hear a hundred NSA assholes tear their hair out

  • source
  • parent
  • hideshow 6 child comments
  • [–] 45 points 1 month ago* (last edited 1 month ago) (1 child)

    20 years of hoarding CVEs down the drain.

    Now they'll never be able to gg ez their way into any country and will have to actually use their bribery budget to get more implants lol.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 21 points 1 month ago (1 child)

    Keep in mind that the rate of errors caught by AI will not be consistent. It will drop off over time.

    While I'm no fan of AI, that has nothing to do with it. Adding AI to error detection suites is (mostly) fine so long as you don't remove more tradional methods like code review, manually set up unit tests, and properly reviewing each failed test instead of just letting the AI slop in a patch.

    My point is that any test you add to an existing codebase is going to catch a decent number of issues at first, then over time it will drop off as pre-existing issues get resolved. Then you'll be left with the lower rate of new issues from updates.

    AI isn't a silver bullet. It (sometimes) is another tool in the toolbox.

  • source
  • parent
  • hideshow 2 child comments
  • [+] -24 points 1 month ago (4 children)

    as we use AI to find vulnerabilities faster (hopefully) than bad actors can use AI to find vulnerabilities.

    Oh small, simple child: who do you think has the better access to AI in the first place?

  • source
  • parent
  • hideshow 8 child comments
  • [–] 25 points 1 month ago* (1 child)

    This is a reminder that US scientists during the cold war thought fish were russian subs because they didn't have biologists on staff

    Judging by the way they've treated big companies in the past the NSA is staffed by a bunch of people who use backroom deals with US tech companies to collect their data mostly.

    I actually think a large plurality of them spend most their time tracking/stalking their wives and like people they argued with the day before.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 1 month ago (1 child)

    small, simple child:

    Didn't downvote you but.....

    LOL! The level condescension sure is right on point Lemmy.That genuinely got a chuckle. In some ways I enjoy being that simple child. Full of wonderment at this universe around him.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 1 month ago (1 child)

    The companies who are training AI... On Linux servers?

    Wait no, obviously smaller actors you're referring to with your mysterious comment.

    Or maybe all the follow on tech companies that are the largest customers using AI aaand who also mostly use Linux

    No no I've got it wrong, US government entities want a backdoor so restrict AI releasing, then during that window exploit non-US companies using Linux

  • source
  • parent
  • hideshow 2 child comments