Submitted by twovests in technology

Patches on closed-source operating systems like iOS or Android provided very useful resources for reverse-engineering teams to be able to create a useful exploit. Patches on open-source operating systems worked the same way. Nation-states and other hacking groups would always take a look at it.

But this took time and expertise which was really rare. We're seeing exploits published from Linux patches within hours of the patch (probably LLM assisted) for vulnerabilities which were discovered using LLM assistance in the first place.

We're on our third high-profile CVE following a trend like this this week.

Anyways, Jstpst has the mitigation for the latest Linux exploit

1

Comments

You must log in or register to comment.

twovests OP wrote (edited )

oh god dammit there's ANOTHER new exploit

*edit: Nope, "Copy Fail 2 electric boogaloo" is just the reverse-engineered exploit that resulted in DirtyFrag being announced early despite the embargo. Same vuln

1

twovests OP wrote

I guess someone sees LLMs mentioned and downvotes by instinct? But these are real things that are new and happening now that we have to deal with. It's not like we should just ignore exploits or patches for being LLM assisted.

The "Our new model is sooo powerful and scary" "Nuh uh, OURS is" is mostly hype and bullshit. But we've been doing automated vuln discovery and reverse engineering forever, and now it works a little bit better.

1