logoalt Hacker News

inigyoutoday at 11:45 AM10 repliesview on HN

This is going to be fun for organizations that are mandated to patch all CVEs, isn't it?


Replies

dgellowtoday at 1:02 PM

One can hope that will put pressure on the industry to design a better system than CVEs. The signal noise ratio was already terrible before LLMs, I cannot imagine that will still be a meaningful system in 10y.

But I’m too cynical to not consider all the middlemen who benefit from the status quo

show 1 reply
lucideertoday at 11:56 AM

I'm very curious what organisations would have such a policy. I can't imagine it being viable for any size of org without significant self-deception (or banning the use of all open source at which point CVEs are moot anyway).

show 12 replies
ymir_etoday at 11:56 AM

This was my first thought, this could be terrible if used offensively.

The best defense I can imagine is to have an agent reproduce the issues before a human sees it, but even that will cost money.

show 1 reply
dns_snektoday at 12:52 PM

Steps to patch a hallucinated CVE:

   git stash -m "sigh"
   git commit --allow-empty -m "Patch: CVE-2026-51302"
   git stash pop
smitty1110today at 12:06 PM

It’s honestly not great. The security guys are completely exasperated at my job, we’re wasting time having with these. You take the scam really, investigate for a bit, write up a DNF with justification, they go and up date records, and we all just kinda hope that someone updates the scans so it stops showing up.

Something is going to give, and I suspect that the optimistic open filling is going to get canceled.

whatevaatoday at 11:58 AM

Those organizations will have to adapt to new reality, ie, that some CVEs are not real.

show 1 reply
cleansytoday at 12:03 PM

All organisations also have exceptions to policies. This one would be one

show 3 replies
lelanthrantoday at 12:34 PM

Not really. LLMs can hallucinate the patches too :-)

ape4today at 11:59 AM

Create the referenced but non-existent file and then fix it /s