@miramurati Same ol’ boring stuff. Look at the latency with which the model responds to an interaction. Also, this is nothing which OpenAI can’t dismantle in a week of time.
Not surprising to watch the security community go through the five stages of grief now that LLMs are bulldozing the busywork layer we used to confuse with skill.
@LiveOverflow AI compresses a lot of the search/execution layer, but real pentesting still depends on judgment: what to chase, what to ignore, and where depth actually matters. Broad automated coverage isn’t the same as a real assessment. Hard CTF challenges still bottleneck on correct insight
@sracha What baseless reasoning and an attempt to make her choice seem rational and objective? The height difference between the couple has no bearing on the mortality rate during childbirth. @theweb3jess
@smackingg They definitely treated you differently by assuming you’re Kurdish or Middle Eastern. Japanese people can be incredibly racist (passive-aggressive) toward those who fit that appearance.
LLM wrapper “security” startups:
1.“AI autonomously finds vulns + variants + patches”
2.“AI gives SMEs vuln primitive checks to assist”
In reality: a pitch deck, prompts, tools, rented intelligence from the same model providers with no means to solve deep security problems.
This!
Security research isn’t “vibe coding.” You’re working in an unbounded problem space where you actually have to connect dots and understand systems E2E. There’s no cheap “success” signal like in software dev (builds pass, tests green) telling you you’re done.
#React2shell
When the POC comes out, it’ll be a humbling moment for LLMs and how we use them. What’s circulating is extremely naive and incorrect.
Experienced engineers are sharing plausible-sounding hallucinations from frontier models.
Reminder to bump React, Next & frameworks.
Pretty sure every LLM-wrapper startup has a few “human researchers” tearing into this right now, purely so they can brag their agent “discovered” the exploit in the launch blog.
#React2Shell#CVE-2025-55182 #CVE-2025-66478