logoalt Hacker News

happyopossumtoday at 4:51 PM0 repliesview on HN

> Backing exploit PoCs out of patches, commit messages, and random overheard or over-read sentences is a practice as old as vulnerability research

True, but it used to take days or weeks of research, testing, and RE to get those PoCs.

Today the entire chain - reading commits, RE patch binaries, building exploit, scripting exploit scan, $profit - can be fully automated and happen in minutes or hours.