@Mister_Ch0c Agreed. CTF is already heading into that structure. Top players are also using AI now, and what decides most challenges seems to have come down to things like parallelizing models and automating flag submission.
Duplicated 🤗 I also landed a VM escape and reported it with a working PoC on March 27 — one response on April 7, then it stalled. Not a who-was-first thing; such collisions will only get more common in the AI era.
@arinerron thanks for the reply! what a coincidence! it really does feel like a bit of a gold rush. the quieter corners of large codebases make for such a fun playground
Duplicated 🤗 I also landed a VM escape and reported it with a working PoC on March 27 — one response on April 7, then it stalled. Not a who-was-first thing; such collisions will only get more common in the AI era.
There's another one I haven't published ― a different-root-cause VM escape. Given QEMU's position that "non-virtualization use case" issue are bugs rather than vulnerabilities, I'm honesty unsure it's even worth releasing.