Your contract with a software vendor is one of the highest security leverage points you have. Demand they use the latest frontier models to continually improve the security of that code base, and to demonstrate evidence of that effort every quarter.
I have a personal update: Next monday, I will be starting at @OpenAI working on better cyber (which will also entail some efficiency work). I'm pretty excited about the things I will learn and the things we will do.
The Node.js sandbox library vm2 has disclosed a critical vulnerability that allows attackers to escape the sandbox and execute arbitrary code. The exploit is public, the CVSS score is 9.8, and any use of vm2 v3.10.1 or earlier should be considered affected. Immediate upgrade is recommended.Learn more in our blog post from @InsiderPhD and Kurt Boberg.
https://t.co/RZlkg1O4Pp
I find it fascinating that `gpt5-codex` is making the same mistake often when generating a SARIF file. The last "locations" object is not properly closed and it closes the array before... then it craps out.
Ok, so this MUST be the attackers behind Nx at play. I just started analyzing the exfil mechanism through GitHub repos, and wow... This is bad news. We've got a worm on our hands.
@IceSolst Re: comparing with Semgrep, we're trying to make sure we don't fall into the "LLMs suck Semgrep is the best" though and go past the product into the what does the future of SAST look like with LLMs
ty, our upcoming static type checker and language server for Python, is accidentally on the front page of HN.
We're rapidly closing in on an initial "experimental preview release"...
New export controls incoming, Bloomberg reporting:
"But if an AI company wants to fine-tune a general-purpose open weight model for a specific purpose, and that process uses a significant amount of computing power, they would need to apply for a US government license to do so in a Tier 2 country."
Controlling who in the entire world can finetune on what seems like a losing and generally bad proposition.
Having seen xbow in action: if you’re making a living from bug bounties, and relying on generic vulnerability classes, I would consider alternative career plans