Post #2246712
2026-05-06 19:29 UTC
Replies (4)
-
@GuillaumeRossolini@infosec.exchange 2026-05-06 19:58
@dangoodin@infosec.exchange lol? Do they believe so much in AI now that they’d throw everything at it What about their own longstanding “IRL: online life is real life” podcast that used to call out AI overreach, dangers and mismanagement
-
@szbalint@mastodon.social 2026-05-06 20:05
@dangoodin@infosec.exchange What is the CVSS distribution of the 271 bugs that they’ve found with Mythos help? (Or some cruder severity/exposure metric if they don’t have CVSS)
-
@lmk@infosec.exchange 2026-05-06 20:12
@dangoodin@infosec.exchange "Aren't you confusing the number Found by Mythos with the actual number of vulnerabilities (still unfound)?" The title suggests the unknown vulns are out of sight out of mind. We can be nearly certain Mythos didn't find the all and we cannot put an upper bound on the number. Also an important question is "Breakdown the 271 by severity and confirmed exploitable."
-
@bertdriehuis@infosec.exchange 2026-05-08 11:00
@dangoodin@infosec.exchange how many of these vulnerabilities had easy fixes, without side effects? I've lost count of how often I fixed bugs, only to find out that the fix caused a bigger problem down the line. In the early days of Firefox I helped fix issues in the code, and verifying the fix for regression potential is ten times the work of the fix itself.