Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
goobreee
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
goobreee
14d ago
i think a key missing part is that an LLM on its own can't find vulnerabilities, so it's always an AI + harness. even mythos, when used for finding zero-days, is using an actually surprisingly heavy handed and expensive scaffold
2.
▲
by
goobreee
15d ago
i don't think this is correct. if you look at this article by the curl founder daniel stenberg ( https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v... ), he talks about how he previously ran
3.
▲
by
goobreee
15d ago
i don't think this is doable fairly. as they say in the blog post, the only fair way to is to look for new, previously undiscovered zero-days, otherwise you always risk the model has in some way been trained on the vulnerabilities. loo
4.
▲
by
goobreee
15d ago
I think you might be misunderstanding this? This is, from my understanding, what went down: 1. curl was scanned by many different things, including AISLE, and many bugs were fixed <- all this was in the past 2. curl a week ago was scanne
5.
▲
Six curl CVEs after OpenAI and Anthropic came back with zero
(aisle.com)
183 points
by
goobreee
15d ago
|
66 comments
6.
▲
"Mythos" at Home, and It's Called Aisle
(stanislavfort.substack.com)
7 points
by
goobreee
3mo ago
|
0 comments