D•Scribe
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
☆ Yσɠƚԋσʂ ☆@lemmygrad.ml to technology@hexbear.netEnglish · 1 day ago

Google says its AI-based bug hunter found 20 security vulnerabilities

techcrunch.com

external-link
message-square
30
link
fedilink
  • cross-posted to:
  • technology@lemmy.zip
  • technology@lemmygrad.ml
26
external-link

Google says its AI-based bug hunter found 20 security vulnerabilities

techcrunch.com

☆ Yσɠƚԋσʂ ☆@lemmygrad.ml to technology@hexbear.netEnglish · 1 day ago
message-square
30
link
fedilink
  • cross-posted to:
  • technology@lemmy.zip
  • technology@lemmygrad.ml
Google says its AI-based bug hunter found 20 security vulnerabilities | TechCrunch
techcrunch.com
external-link
The discoveries by an AI-based bug hunter are significant, as it shows these tools are starting to get real results, even if they still need a human.
alert-triangle
You must log in or # to comment.
  • hello_hello [comrade/them]@hexbear.net
    link
    fedilink
    English
    arrow-up
    33
    ·
    1 day ago

    “Hey google can you publish the bug hunter AI and its details so we can verify?” doggirl-smart

    porky-happy : “no”

    doggirl-sleep

    • Palacegalleryratio [he/him]@hexbear.net
      link
      fedilink
      English
      arrow-up
      4
      ·
      12 hours ago

      The Aurora Borealis? At this time of year? At this time of day? In this part of the country? Localized entirely within your kitchen?

      Yes.

      May I see it?

      No.

    • combat_brandonism [they/them]@hexbear.net
      link
      fedilink
      English
      arrow-up
      21
      ·
      1 day ago

      it-is-known

  • EnsignRedshirt [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    37
    ·
    1 day ago

    Hopefully the automated bug hunters can help keep up with the security vulnerabilities created by AI coding.

    • invalidusernamelol [he/him]@hexbear.net
      link
      fedilink
      English
      arrow-up
      21
      ·
      1 day ago

      Make both of them part of the same reward function so the AI can generate vulnerabilities that the AI can immediately bug hunt.

      • GrouchyGrouse [he/him]@hexbear.net
        link
        fedilink
        English
        arrow-up
        9
        ·
        17 hours ago

        The capitalists finally became job creators

        • invalidusernamelol [he/him]@hexbear.net
          link
          fedilink
          English
          arrow-up
          4
          ·
          11 hours ago

          Number of resolved tickets go up

  • limer@lemmy.ml
    link
    fedilink
    English
    arrow-up
    17
    ·
    1 day ago

    I’ll reserve judgement until after the bugs are published. Until then, I am expecting minor issues only

    • ☆ Yσɠƚԋσʂ ☆@lemmygrad.mlOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      I mean if these tools help catch any issues in automated fashion that’s still a win.

      • TrashGoblin [he/him, they/them]@hexbear.net
        link
        fedilink
        English
        arrow-up
        12
        ·
        22 hours ago

        The false positive rate makes them a net loss.

        https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/

        • ☆ Yσɠƚԋσʂ ☆@lemmygrad.mlOP
          link
          fedilink
          English
          arrow-up
          2
          ·
          21 hours ago

          That article isn’t referring to the specific system google is using, so we don’t know what the false positive rate is.

          • WrongOnTheInternet [none/use name]@hexbear.net
            link
            fedilink
            English
            arrow-up
            8
            ·
            19 hours ago

            Uh pretty high if it’s an LLM

            • ☆ Yσɠƚԋσʂ ☆@lemmygrad.mlOP
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              18 hours ago

              That’s not a given.

              • GaveUp [she/her]@hexbear.net
                link
                fedilink
                English
                arrow-up
                1
                ·
                3 hours ago

                It’s literally the 2nd paragraph lmao

                Heather Adkins, Google’s vice president of security, announced Monday that its LLM-based vulnerability researcher Big Sleep found and reported 20 flaws in various popular open source software.

              • Orcocracy [comrade/them]@hexbear.net
                link
                fedilink
                English
                arrow-up
                7
                ·
                17 hours ago

                But it is likely.

                • ☆ Yσɠƚԋσʂ ☆@lemmygrad.mlOP
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  17 hours ago

                  It really depends on how their particular system is set up. You’re just making sweeping vibe based statements without any evidence to support them.

      • limer@lemmy.ml
        link
        fedilink
        English
        arrow-up
        21
        ·
        1 day ago

        They found ten issues, but how many hours spent filtering out the false positives?

        • ☆ Yσɠƚԋσʂ ☆@lemmygrad.mlOP
          link
          fedilink
          English
          arrow-up
          1
          ·
          21 hours ago

          We don’t know, however of this is security related issues then it doesn’t matter. The cost of a breach would be obviously higher.

          • Le_Wokisme [they/them, undecided]@hexbear.net
            link
            fedilink
            English
            arrow-up
            5
            ·
            20 hours ago

            compare to the cost of humans finding them the normal way, not whatever breach you’re imagining.

            • ☆ Yσɠƚԋσʂ ☆@lemmygrad.mlOP
              link
              fedilink
              English
              arrow-up
              1
              ·
              20 hours ago

              Clearly the humans didn’t find them the normal way, because they wouldn’t be there to be found otherwise would they?

              • WrongOnTheInternet [none/use name]@hexbear.net
                link
                fedilink
                English
                arrow-up
                2
                ·
                10 hours ago

                The last time Google did a media run about Deepmind finding bugs, it related to a vulnerability on an dev branch that hadn’t been deployed yet (and was not likely to have been with the vulnerability).

                • ☆ Yσɠƚԋσʂ ☆@lemmygrad.mlOP
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  10 hours ago

                  So it found a vulnerability in the code it was given. 🤷

              • limer@lemmy.ml
                link
                fedilink
                English
                arrow-up
                3
                ·
                17 hours ago

                We don’t know the details yet. Maybe they have a great new tool; perhaps they picked projects that are not maintained so well.

                It will be awesome if they found bugs in curl, not so good to show if they picked my project.

                What they did will be revealed in time

                • ☆ Yσɠƚԋσʂ ☆@lemmygrad.mlOP
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  17 hours ago

                  I’m sure we’ll get more info in due time.

technology@hexbear.net

technology@hexbear.net

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@hexbear.net

On the road to fully automated luxury gay space communism.

Spreading Linux propaganda since 2020

  • Ways to run Microsoft/Adobe and more on Linux
  • The Ultimate FOSS Guide For Android
  • Great libre software on Windows
  • Hey you, the lib still using Chrome. Read this post!

Rules:

  • 1. Obviously abide by the sitewide code of conduct. Bigotry will be met with an immediate ban
  • 2. This community is about technology. Offtopic is permitted as long as it is kept in the comment sections
  • 3. Although this is not /c/libre, FOSS related posting is tolerated, and even welcome in the case of effort posts
  • 4. We believe technology should be liberating. As such, avoid promoting proprietary and/or bourgeois technology
  • 5. Explanatory posts to correct the potential mistakes a comrade made in a post of their own are allowed, as long as they remain respectful
  • 6. No crypto (Bitcoin, NFT, etc.) speculation, unless it is purely informative and not too cringe
  • 7. Absolutely no tech bro shit. If you have a good opinion of Silicon Valley billionaires please manifest yourself so we can ban you.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 416 users / day
  • 813 users / week
  • 1.46K users / month
  • 1.71K users / 6 months
  • 2 local subscribers
  • 23.9K subscribers
  • 374 Posts
  • 2.49K Comments
  • Modlog
  • mods:
  • context [fae/faer, fae/faer]@hexbear.net
  • EmmaGoldman [she/her, comrade/them]@hexbear.net
  • SexUnderSocialism [she/her]@hexbear.net
  • gaycomputeruser [she/her]@hexbear.net
  • ZoomeristLeninist [they/them, she/her]@hexbear.net
  • UI: unknown version
  • BE: 0.19.12
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org