← Back to context

Comment by devy

16 hours ago

This is probably still considered standard response timeline, not a rapid one.

The time window allowing for CVEs + Vulnerabilities remediation has been collapsing to days and hours perhaps even minutes[1]. Anyone who has an OpenRouter account can start using Strix + GLM 5.3 Flash to do damages at frontier Mytho 5 level cyber capabilities. [2]

This cyber patching race is on, won't stop until all the software created for the past 70 years still in active use needs to be patched up. This is happening at EVERY SINGLE software company.

The cost of not doing it? Game over.

[1]: https://news.ycombinator.com/item?id=49705036

Meanwhile I have customers running legacy web apps last compiled over five years ago on end-of-life operating systems… and it’s crickets chirping. Dead quiet, not even a hint of an attack, let alone a breach.

I expected them to have been hacked to pieces by now, but even “maximally vulnerable” internet-facing apps seem to be relatively unmolested so far.

Maybe it’s still too expensive to go after “boring” enterprise targets? Maybe the bad actors targeted crypto systems first for the immense payoffs, if successful?

  • > it’s still too expensive to go after “boring” enterprise targets?

    The economic argument seems convincing to me. I can’t tell what your stance on it is.

    You’re the only one that knows the value of these targets, but “not worth it” seems likely to me.

    • It's a risk-reward ratio, same as anything else, whether legal or illegal.

      You wouldn't organise the equivalent of an elaborate bank heist to break into a child's piggy bank, it's just not worth it.

      I have heard of a few high profile crypto heists that appear to be AI-assisted, some as far back as the GPT 3.5 era. There was an article I can't find any more about someone accidentally pushing a security fix to a public repo and getting their wallets drained via that specific mechanism within something like an hour.

      Malicious actors are watching crypto like a cat in front of a mouse hole, because a "success" can net them the equivalent of hundreds of millions of USD that they can instantly transfer, launder, and spend.

      For comparison, what would they achieve by hacking the web site of a local council or public library? Cause some embarrassment? Attempt to crypto-locker them? What are the chances of a payout? Certainly not a 100%, and you're also certain to get the attention of the local equivalent of the FBI or Homeland Security.

  • Anyone can push people onto the railway tracks at a metro station but they don't. Being able to cause damage doesn't mean people will.