惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
有赞技术团队
有赞技术团队
J
Java Code Geeks
H
Hackread – Cybersecurity News, Data Breaches, AI and More
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
C
Check Point Blog
博客园 - 【当耐特】
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
The Cloudflare Blog
Microsoft Azure Blog
Microsoft Azure Blog
腾讯CDC
Vercel News
Vercel News
IT之家
IT之家
MyScale Blog
MyScale Blog
博客园_首页
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
罗磊的独立博客

Hacker News: Ask HN

The New Window Delete ChatGPT Atlas Spyware Tell HN: Qwen Free Tier Is Discontinued Ask HN: SeedLegals Partnerships in London, worth it? Ask HN: How to highlight talent from untraditional backgrounds? Ask HN: We dont need a programming language now? Durable Object alarm loop: $34k in 8 days, zero users, no platform warning What if Time at the subatomic level has multiple arrows? How to add MidnightBSD Key to UEFI Secure Boot DBX? (Revoked and Forbidden Keys) Ask HN: What's your experience working at xAI as an AI tutor? Any engineers here with experience of clinical data standards? Ask HN: Who is using OpenClaw? Agent Skills for Software Test Automation Ask HN: Who needs contributors? Claude Code is thinking too much Ask HN: What Is the Big-O Order of a Jigsaw Puzzle? Ask HN: Stepping into a new role as a Senior, mentoring dos and dont's? Founder from Zurich heading to SF and Austin for the first time Hacker News No Manual Screenshots: I Built a Scalable Screenshot API Using Cloud Playwright Ask HN: Thought experiment: AGI giving us answers we don't like? Ask HN: I quit my job over weaponized robots to start my own venture 1% Vacancy, 81% Preleased: Where Midmarket Compute Deploys in 2026 Ask HN: Preferred pricing model for sound effects libraries? Copy of the email I sent to my undergraduate professors on Nov 30, 2025 Model API Performance | Hacker News Ask HN: Are open-weight LLMs the new offline encyclopedias? Valgrind 3.27 RC1 is out Claude Code OAuth down for >12 hours Ask HN: What's Better?–Tauri or Electron?
Speed Matters: Why AI Software Vulnerability Exploitation...
randersson10 · 2026-04-23 · via Hacker News: Ask HN

I co-founded a successful security company close to the Mythos ecosystem and have spoken with participants in the know and I am deeply concerned. We, collectively, have answers for some but not all of the problems ahead but are overlooking the speed at which we can apply fixes even if they magically are generated instantaneously by Mythos.

Here are some considerations to consider:

More Vulnerabilities Are Coming: Supposedly Mythos can find vulnerabilities more effectively, many models can do this, but the claim it can find them more acutely. Based on the momentum of the models, others will follow and we can all agree that many more vulnerabilities will be found in the future. The supposedly game changer with Mythos is not the finding, it is chiefly because it can chain these vulns together sequentially to develop exploit chains and is creative/innovative in doing so. Anthropic claims Mythos can also be used to provide FIXES as well, I am not convinced about that. I believe it will FIND more than it can FIX. But even if it can FIND and FIX at the same rate, which it can’t, there is a whole other aspect that is being overlooked. How long it takes to get these FIXES deployed. Even if it can fix all of them it takes time to get these patches into the software upstream because they have to be accepted and TESTED and there is an entire approval process and release process. It’s not instantaneous. Typically a patch takes days even weeks to move through the upstream ecosystem before it becomes available to the general public. Here is the AI generated timescales for a critical vuln: Upstream Fix: 24–48 hours after confirmation by the core project team. Downstream Packaging 12–48 hours for major distros (Ubuntu LTS, RHEL, Debian Stable) to backport and test. Availability to User: 2–5 days from the initial public disclosure of the vulnerability. For arguments sake lets assume we shrink that down to a day. Magically. Then the end users themselves must take these patches and apply them to their infrastructure. This requires another QA cycle at least. These stats are AI generated YMMV: but for Log4J, by Day 10: On average, organizations had patched only 45% of their vulnerable cloud resources. Average Remediation Time: For systems that were detected and tracked, the average time to remediate was 17 days. Priority Patching: Externally-facing systems (those most at risk) were patched faster, averaging about 12 days, while internal systems lagged behind. The 1-Year Mark: By late 2022, telemetry from security firms like Tenable showed that 72% of organizations still had at least one vulnerable Log4j instance in their environment. The U.S. Department of Homeland Security's Cyber Safety Review Board (CSRB) stated that Log4j is a "endemic vulnerability" and predicted it will take a decade or longer to fully eliminate it from the global software supply chain. A DECADE!!

So there is a massive timing problem even if FIND to FIX rate is the same which it won’t be, the entire downstream system cannot move at the right speed to get the fixes deployed into the infrastructure. This all sucks up developer time and cost as teams pivot to emergency mode etc. It’s just a scary prospect.

This is what we are facing. Please can you make suggestions in terms of what you are planning on doing to find and apply patches faster, so that we can get some creative ideas around best practices. We have other things we are doing that solves some of these issues but the speed timing issue is the one that is being overlooked in this entire debate.

Russ from RapidFort