The Bard's Lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Nobody@lemmy.world to Linux@lemmy.ml · 30 days ago

The zero-days are numbered | The Mozilla Blog - Firefox 150 includes fixes for 271 vulnerabilities identified during this initial evaluation [of Mythos Preview]

blog.mozilla.org

external-link
message-square
28
link
fedilink
126
external-link

The zero-days are numbered | The Mozilla Blog - Firefox 150 includes fixes for 271 vulnerabilities identified during this initial evaluation [of Mythos Preview]

blog.mozilla.org

Nobody@lemmy.world to Linux@lemmy.ml · 30 days ago
message-square
28
link
fedilink
The zero-days are numbered  | The Mozilla Blog
blog.mozilla.org
external-link
Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser.
alert-triangle
You must log in or # to comment.
  • brianpeiris@lemmy.ca
    link
    fedilink
    English
    arrow-up
    28
    arrow-down
    1
    ·
    30 days ago

    Some good debunking here: https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/

    • GamingChairModel@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      29 days ago

      This one is the same author addressing this specific Mozilla release.

    • TrackinDaKraken@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      29 days ago

      I got distracted and started searching for pictures of Hawaii beaches.

    • netvor@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      29 days ago

      LOL, Anthropic does rhyme with Titanic. cOiNcIdEnCe?

  • onlinepersona@programming.dev
    link
    fedilink
    English
    arrow-up
    27
    arrow-down
    1
    ·
    30 days ago

    We’ve led the industry in building and adopting Rust

    Yeah, then you fired the team to pay the CEO a few million more.

  • vermaterc@lemmy.ml
    link
    fedilink
    arrow-up
    25
    ·
    30 days ago

    Defenders finally have a chance to win, decisively

    I’m curious how it will turn out to be in a long term. Are we going to have safer software? Because not only defenders will have a powerful tool, but attackers too. But at the same time, number of bugs is finite… Can we in theory one day achieve literally zero bugs in codebase?

    • brucethemoose@lemmy.world
      link
      fedilink
      arrow-up
      24
      ·
      edit-2
      30 days ago

      It does seem advantageous to the defender.

      Another factor Mozilla didn’t mention (and that Anthropic wouldn’t like to emphasize) is that major LLMs are pretty similar. And their development is way more conservative than you’d think. They use similar architectures and formats, train from the same data, distill each other, further pollute the internet with the same output and so on. So if (for example) Mozilla red teams with Mythos, I’d posit it’s likely that attacker LLMs would find the same already-patched bugs, instead of something new.

      …So yeah. I’d wager Mozilla’s sentiment is correct.

    • [object Object]@lemmy.ca
      link
      fedilink
      arrow-up
      14
      ·
      30 days ago

      You can achieve zero bugs through liberal use of rm.

      • racoon@lemmy.ml
        link
        fedilink
        arrow-up
        6
        ·
        30 days ago

        You can achieve the same effect with a hammer

      • sakuraba@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        29 days ago

        Some LLMs will agree with you

    • Tinidril@midwest.social
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      2
      ·
      30 days ago

      Cyber security in general is going to get interesting. Breaking into protected systems often requires more patience than expertise. Attackers often get detected when they take short cuts because of laziness and overconfidence. AI agents have unfathomable patience and attention to detail.l

      • ☆ Yσɠƚԋσʂ ☆@lemmy.ml
        link
        fedilink
        arrow-up
        7
        ·
        30 days ago

        I don’t really agree with the attention to detail part from my experience. AI agents love to take shortcuts from what I’ve seen, and you have to pay a lot of attention to what they’re doing to make sure they do the right thing.

      • Pennomi@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        30 days ago

        They have attention to detail, just not the right details. It’s super easy for them to get lost in a never ending train of tangents.

    • Nobody@lemmy.worldOP
      link
      fedilink
      arrow-up
      1
      ·
      30 days ago

      Not zero bugs, but it should help. A benefit for defenders is that they can use AI review on code before they make it public or release it in a stable release

  • chonkyninja@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    ·
    29 days ago

    Meanwhile on GitHub Claude Code has over 5k bug reports, currently open.

    • Eric@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      21
      arrow-down
      1
      ·
      29 days ago

      LLMs generate the 0-days, then LLMs remove the 0-days. They will never run out of work!

      • monkeyman512@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        29 days ago

        Makes sense. Trained on software engineers working that pattern for decades.

  • kibiz0r@midwest.social
    link
    fedilink
    English
    arrow-up
    8
    ·
    edit-2
    30 days ago

    How many vulnerabilities would’ve been found if we had spent several million dollars on human security researchers though?

  • utopiah@lemmy.ml
    link
    fedilink
    arrow-up
    5
    ·
    30 days ago

    That doesn’t make sense. Don’t the attackers have the same tools?

    • Nobody@lemmy.worldOP
      link
      fedilink
      arrow-up
      3
      arrow-down
      3
      ·
      30 days ago

      Mythos Preview is better at finding real vulnerabilities than existing public models and, for now, only a few have access to it.

      • Jumuta@sh.itjust.works
        link
        fedilink
        arrow-up
        3
        ·
        30 days ago

        for now

        • 🖖USS-Ethernet@startrek.website
          link
          fedilink
          English
          arrow-up
          3
          ·
          30 days ago

          https://techcrunch.com/2026/04/21/unauthorized-group-has-gained-access-to-anthropics-exclusive-cyber-tool-mythos-report-claims

          That lasted long

          • Jumuta@sh.itjust.works
            link
            fedilink
            arrow-up
            2
            ·
            29 days ago

            bro 3 hours wtf

      • utopiah@lemmy.ml
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        29 days ago

        I’m aware (unfortunately) of the marketing claims and even if they might be true, as you say it is “for now”. So if it’s only temporary for that arm race, especially if held by a company who leaked its own code just days ago, then I have a hard time understanding why ‘zero-days are numbered’ because this title claims the dynamic itself is gone. That’s now my understanding, especially if other models are just marginally (which is hard to prove with models, finding proper metrics) worst than it.

        See comment that shared https://techcrunch.com/2026/04/21/unauthorized-group-has-gained-access-to-anthropics-exclusive-cyber-tool-mythos-report-claims just few hours ago, and that’s not even sophisticated.

        Anthropic and OpenAI have multiple times used this arm race rhetoric before and it worked. Their models are supposedly “too dangerous” to be released thus consequently they have to control access.

        It might be true but so far what we have witnessed is that roughly equivalent models get released by others merely weeks or maybe months after, sometimes open, but the “moat” never lasted long so I’m questioning why it would be different this time.

  • db2@lemmy.world
    link
    fedilink
    arrow-up
    6
    arrow-down
    14
    ·
    30 days ago

    Slopzilla Slopfox 🙄

    This isn’t going to end well.

    • Alex@lemmy.ml
      link
      fedilink
      arrow-up
      7
      arrow-down
      2
      ·
      30 days ago

      If it’s finding valid vulnerabilities then it’s just another tool like static analysis, fuzzers and sanitizers. There definitely seems to be a difference in quality compared to earlier generations that were behind the sloppy avalanch of reports.

    • ArtVandelay@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      29 days ago

      Look, I’m all for fuck AI, but this isn’t that.

      • db2@lemmy.world
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        29 days ago

        It will be. You’ll see.

Linux@lemmy.ml

linux@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@lemmy.ml

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

  • !opensource@lemmy.ml
  • !libre_culture@lemmy.ml
  • !technology@lemmy.ml
  • !libre_hardware@lemmy.ml

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 424 users / day
  • 984 users / week
  • 2.59K users / month
  • 7.16K users / 6 months
  • 2 local subscribers
  • 65.4K subscribers
  • 6.85K Posts
  • 83.5K Comments
  • Modlog
  • mods:
  • AgreeableLandscape@lemmy.ml
  • nooter692@lemmy.ml
  • MarcellusDrum@lemmy.ml
  • Arthur Besse@lemmy.ml
  • Cyclohexane@lemmy.ml
  • BE: 0.19.14
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org