Just stumbled on this…👀
Three live ClamAV 1.5.x memory corruption bugs (double free, ZIP desync that reaches RCE, STATS pointer leak). Full labs, PoCs, and patches already public.
“The vulnerabilities were discovered entirely through AI. Author takes no credit — all glory to the Clankers.”
https://t.co/jnuxu1nm6B
#InfoSec #ZeroDay #ClamAV #AI
Turns out Claude Code is an amazing code signed implant.
Set 2 env vars and it connects to a remote server and hot-loads remote code into the Claude process without touching disk.
Brief time with Fable yesterday got me started on a cool project.
https://t.co/6mYQMkB9fE
WebGPU rendered (no DOM). GitHub REST API-only + built in AI agent with an in-memory shell to help it navigate natural requests.
@bcherny I thought the Cyber Verification Program was created to "enable professionals to continue working on legitimate dual-use tasks safely while minimizing interruption."
I was approved 3 days ago, yet I'm now getting pop-up warnings that my prompts violate the Acceptable Use Policy, with a threat of enhanced safety filters if the pattern continues.
The "Learn More" link sent me to usersafety@, but the instant reply was about appealing a ban I never received. It didn't identify the issue or help at all.
Is there a clearer delineation of what counts as a violation for those approved under the Cyber Verification Program? I'm just trying to do legitimate professional work without getting filtered or banned.
Well, I got approved for the "Cyber Verification Program" followed by a message stating if I continue violating the 'Acceptable Use Policy' they'll apply enhanced safety filters to my chats.
The 'Learn more' button gave me an email to reach out to which I did... got an immediate reply to fill out an appeal for the ban I don't have. So that's cool..?
@UK_Daniel_Card lol dude, mine decided it was tired of 'wasting time' on something it kept generating buggy code for and literally moved on from the task. wild times!