They spent $20k finding their bugs, while I spend less than $1000 on my fuzzing setup and found alot of the same bugs (several in their announcements i found and have in my 'to report' docs since they werent exploitable beyond DoS). i havent found 'thousands' but i have found nearly 1000 since December. And the VAST majority that have been found with AI and fuzzing are Null Ptr Derefs. and as mentioned, they are almost never exploitable on modern systems since memory at 0x0000000 cant be mapped to anything anymore. (it cant with like +8/16/32/64 offsets either, i forget what the first usable spot is but its not anywhere near a null ptr deref location). Mythos might be good at finding bugs, but it is not finding things that would set the internet on fire in most instances. im sure they found some nice bugs in their thousands, but most of them would be DoS impact at absolute most.
With worries about supply-chain attacks on the Python ecosystem, I wrote a few lines about my preferred development set-up, and how it adapts well to vibe-coding and mitigates many (if not all) risks.
We are very excited to share our last research work: 𝐄𝐔𝐂𝐋𝐄𝐀𝐊, authored by Thomas Roche.
An electromagnetic Side-Channel Vulnerability in the ECDSA implementation of all Infineon security microcontrollers, notably impacting all YubiKey 5 Series.
https://t.co/CUqmlUTRh8
Our Director of Product Security Architecture, Sebastien Riou, recently spoke with @DanielNenni of Semiwiki on when and how to migrate to Post Quantum #Cryptography.
To listen to the webinar recording in full, visit:
https://t.co/sI0HHzqKwJ
#PQC#NIST#postquantum
@antriksh_s My HK taxi driver back in 2011. He also constantly switched between 3-5 calls using different headsets. I think he was running some kind of betting studio
🚨BIG NEWS🚨
Today @NIST has published the #PQC standards! FIPS 203, FIPS 204 and FIPS 205 are official! Congrats to the entire cryptography community! This triggers the most significant cybersecurity transition in history...
More info on our blog: https://t.co/BRPSiYHGsO
I recently found an exploitable timing leak in the reference implementation of Kyber (ML-KEM), the soon-to-be NIST standard for post-quantum key encapsulation.
Let’s see if you can spot it in the source code - msg is secret: