Aug ’25: AI traced CVEs to root cause functions. Rust & Java :white_check_mark:, Ruby :warning:. Data gaps caused most fails. Updated agent (Nov) is stronger—new results soon.
#Cybersecurity#AIsecurity#CVE#LLM
https://t.co/b1oYV4BYUC
🎉 Rust turns 10 today! 🦀
From the birth of Ferris the crab to powering safe, fast systems—what a journey.
We're celebrating: iCR now supports Rust, finding bugs others miss.
Try it: [email protected]#RustLang#Rust10#FerrisTheCrab#SecureCode
Winter is coming!! You need signals about unknown bugs in your code more than ever before! Not just signals but better signals than just known CVEs from the past
https://t.co/5V8636XWak
Thank you @openssf and @alphaomega Our @muna_haf and @Fazledyn are finding and fixing bugs at scale in open source projects, so far have triaged 1,079 open source projects and submitted 168 bug reports.
https://t.co/r59dilg7Qf
#oss#osssecurity
Now live, the ability to open up temporary private forks on GitHub security advisories via API!
Imagine a world where security researchers can remediate vulnerabilities in bulk across hundreds repositories. That's what we're working towards!
https://t.co/XnLgYiosez
Arafat Tanin writes about how small mistakes in Java Serialization can cause big problems.
This is a part of a series of posts on small mistakes in code that can hurt big time. The work is done with support from @AlphaOmegaOSS and @openssf
https://t.co/XfSPQvEOjp
Red Hat Trusted Application Pipeline will be a game changer in building secure and trusted DevOps pipeline. We are happy to be involved.
#redhatsummit2023 https://t.co/1A3it0k5Vr
I want to get your thoughts on a couple of things.
Think of a company writing proprietary code. For something like GitHub Copilot X, do you think that people will be worried about sharing their code snippets when they are asking questions to large langu…https://t.co/ePU5lIKlCa