Significant raise of reports [LWN.net]
And we're now seeing on a daily basis something that never happened before: duplicate reports, or the same bug found by two different people using (possibly slightly) different tools. It's a bit scary (and tiring), but at least compared to the previous era of AI slop, you feel like you're not working for nothing because bugs get fixed. Also it's interesting to keep thinking that these bugs are within reach from criminals so they deserve to get fixed. I don't know how long this pace will last. I suspect that bugs are reported faster than they are written, so we could in fact be purging a long backlog (and I hope so). Something I'm predicting is that at least it will change the approach to security fixes: - embargoes will probably disappear, and for good: what's the point of hiding something that others can instantly find? I have not seen one in a while and that's good. - people will finally understand that security bugs are bugs, and that the only sane way to stay safe is to periodicall
Significant raise of reports [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Register Significant raise of reports Significant raise of reports Posted Mar 31, 2026 17:11 UTC (Tue) by wtarreau (subscriber, #51152) Parent article: Vulnerability Research Is Cooked (sockpuppet.org) On the kernel security list we've seen a huge bump of reports. We were between 2 and 3 per week maybe two years ago, then reached probably 10 a week over the last year with the onl
Explore this link on the map →related reading
- Vulnerability Research Is Cooked - Quarrelsomesockpuppet.org
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Mythos finds a curl vulnerability | daniel.haxx.sedaniel.haxx.se
- Security incident disclosure — July 2026huggingface.co
- Building Pi With Pi | Armin Ronacher's Thoughts and Writingslucumr.pocoo.org
- A Bunch of Programming Advice I'd Give To Myself 15 Years Ago | Marcus' Blogmbuffett.com
- FIRST Mid-Year Vulnerability Forecast Confirms Historic Surge, Projects ~66,000 CVEs in 2026first.org
- Thoughts on slowing the fuck downmariozechner.at
- The bogus CVE problem [LWN.net]lwn.net
- Bug Triage: Definition, Examples, and Best Practices | Atlassian | Atlassianatlassian.com
- Now – Updates from the Linear teamlinear.app