← Back to context

Comment by pixl97

3 days ago

Ya, we're seeing posts talking about the absolutely massive increase in the number of patches in the past few months. It seems some people cannot connect that to the increases in model capabilities.

In groups that have been given a large amount of capacity by the providers, they tend to find huge numbers of new vulns in most of their existing software, and the models can chain together exploits very well.

A number of large companies are absolutely panicked about this now after using these models on their internal systems and the ease at which they broke in. Of course they are not going to discuss this widely as it makes them look bad.

I mean if you gave me direct access to all your source code and fuzzers I could find vulnerabilities as well, these models also are allowed to use fuzzing and static analysis tools to help guide them.

The problem is the sheer scale of it, I could find 1 in a day or two.

They find dozens well depending on how much you are willing to spend ofc. I don't think it's massive in terms of how intelligent these are but how much they can understand intent and execute with relatively fuzzing or incorrectly built tools.

In big companies even most employees don't have access to all the code to be able to figure out the attacks quickly enough.

Somehow they are now willing the red tape since these systems could theoretically with much greater effort(read spend) reverse engineer APIs and break through even without access to the source code.