Of course they are… that’s what CVEs are all about!
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
Only the dead have seen the end of zero-days.
I'm very torn on Mozilla collaborating with not only slop conductors, but crypto bros as well.
I get the issues with image generation and using text generation in scams etc. but as a professional coding tool (not just vibe coding slop) AI can be extremely helpful certain tasks, and this use case, where organizations just don't have the resources to have a security expert pore through millions of lines of code for bugs, is a net positive.
I think this is a case of "don't throw the baby out with the bathwater" we can absolutely still criticize the industry and specific companies for IP, societal, and environmental concerns but lets not turn away a win just because they're causing harm elsewhere.
The AI will exist either way, and people who use that AI will discover these exploits with it. I'd rather it be Mozilla.
That's why Servo and Ladybird need to be vastly built up
bad news, ladybird is all in on slop too
but servo should be fine, in fact right now they have an explicit anti-ai policy!
Hopefully not, but it makes you wonder how many vulnerabilities they might be introducing by fixing others...
This is uplifting news