It's hard to imagine a frontier model being proficient at finding vulnerabilities, but not so proficient at exploiting them.
Surely finding is the hard part, and any LLM should be able to easily exploit a vulnerability it already knows about?
No, this is not the case for human security researchers and I don't see why it should be true for LLMs.
No, this is not the case for human security researchers and I don't see why it should be true for LLMs.