Andrey Lukashenkov’s Post

2,436 vulnerabilities found. 53 of them have a #CVE. Z.ai put up a public disclosure ledger for #GLM 5.3 - 269 #opensource projects, 1097 rated critical or high, and 2383 still under #embargo. Anthropic published the same shape in the spring. #Glasswing reported 23,000+ potential vulnerabilities across H1 and 126 of those became published CVE records, per the Cloud Security Alliance write-up. Two labs, two continents, same bottleneck. #AI made finding cheap. #CVD is still not, and four months of a second lab working the same problem has not made it cheaper. An embargo queue is not a failure state, it is what coordinated #disclosure looks like in the middle - but 53 out of 2,436 is a queue and nobody has built the thing that drains it. The oldest flaw was introduced in 1981. The average one sat there for 26.6 years before anyone found it. Somebody is still running code written before most of the developers reading this were born. And the distribution slopes down toward 2026, which is not code getting safer. However it is probably a statement about which codebase got scanned. Last thing, from the same screenshot: every CVE on that page opens on hover - published date, #EPSS, exploit count, references - no click. That is the free Vulners #Chrome extension. https://cvd.z.ai/ #informationsecurity #vulnerabilityassessment #vulnerabilitymanagement

  • No alternative text description for this image

machine-speed discovery/exploit needs machine-speed defense and that's what we're providing at Miggo.

See more comments

To view or add a comment, sign in

Explore content categories