logoalt Hacker News

Natsutoday at 6:58 AM6 repliesview on HN

I worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.


Replies

Cider9986today at 7:29 AM

Mythos found only one. Would have to be pretty serious bad guys.

https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...

show 1 reply
prmoustachetoday at 9:00 AM

The bad guys wouldn't have submitted a vuln report anyway.

show 1 reply
victorbjorklundtoday at 8:25 AM

Pretty sure if you find a zero day in a software like that you don’t wait until a certain month.

bvcptoday at 7:52 AM

if a company has a problem with this pay for support if its not worth the money …

Cthulhu_today at 9:56 AM

Cool, then it's down to everyone using this library to figure out how they can minimize the impact of a zeroday in curl - security should never be down to a single part of a system.

shevy-javatoday at 9:03 AM

Is this likely though? If you are an AI slop model that spams out finding bugs and vulnerabilities, would you want to become more active when you see that a project is not actively fixing bugs? Because in my opinion, it really would not matter for any AI model how active a project is, when it comes to FINDING existing loopholes.

In other words, I would always go at full speed (as an evil AI slop model) and most likely never release any findings of flaws and loopholes, so they can be exploited lateron. Bad folks don't want to be caught; remember the xz utils backdoor.

I am sure some AI slop models are used by criminals. And they may exploit things at a later time, but they most likely have found issues already. Not every AI slop model would report.

The notion of "the bad guys will now be more active" is strange really in the AI slop age. (We had the stone age; now we have the slop age)