惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
雷峰网
雷峰网
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog
Y
Y Combinator Blog
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
小众软件
小众软件
G
Google Developers Blog
云风的 BLOG
云风的 BLOG
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
量子位
The Cloudflare Blog
T
The Blog of Author Tim Ferriss
博客园_首页
B
Blog RSS Feed
Hugging Face - Blog
Hugging Face - Blog
IT之家
IT之家
阮一峰的网络日志
阮一峰的网络日志
L
LangChain Blog
宝玉的分享
宝玉的分享

Hacker News: Ask HN

The New Window Delete ChatGPT Atlas Spyware Tell HN: Qwen Free Tier Is Discontinued Ask HN: SeedLegals Partnerships in London, worth it? Ask HN: How to highlight talent from untraditional backgrounds? Ask HN: We dont need a programming language now? Durable Object alarm loop: $34k in 8 days, zero users, no platform warning What if Time at the subatomic level has multiple arrows? How to add MidnightBSD Key to UEFI Secure Boot DBX? (Revoked and Forbidden Keys) Ask HN: What's your experience working at xAI as an AI tutor? Any engineers here with experience of clinical data standards? Ask HN: Who is using OpenClaw? Agent Skills for Software Test Automation Ask HN: Who needs contributors? Claude Code is thinking too much Ask HN: What Is the Big-O Order of a Jigsaw Puzzle? Ask HN: Stepping into a new role as a Senior, mentoring dos and dont's? Founder from Zurich heading to SF and Austin for the first time Hacker News No Manual Screenshots: I Built a Scalable Screenshot API Using Cloud Playwright Ask HN: Thought experiment: AGI giving us answers we don't like? Ask HN: I quit my job over weaponized robots to start my own venture 1% Vacancy, 81% Preleased: Where Midmarket Compute Deploys in 2026 Ask HN: Preferred pricing model for sound effects libraries? Copy of the email I sent to my undergraduate professors on Nov 30, 2025 Model API Performance | Hacker News Ask HN: Are open-weight LLMs the new offline encyclopedias? Valgrind 3.27 RC1 is out Claude Code OAuth down for >12 hours Ask HN: What's Better?–Tauri or Electron?
Speed Matters: Why AI Software Vulnerability Exploitation...
randersson10 · 2026-04-23 · via Hacker News: Ask HN

I co-founded a successful security company close to the Mythos ecosystem and have spoken with participants in the know and I am deeply concerned. We, collectively, have answers for some but not all of the problems ahead but are overlooking the speed at which we can apply fixes even if they magically are generated instantaneously by Mythos.

Here are some considerations to consider:

More Vulnerabilities Are Coming: Supposedly Mythos can find vulnerabilities more effectively, many models can do this, but the claim it can find them more acutely. Based on the momentum of the models, others will follow and we can all agree that many more vulnerabilities will be found in the future. The supposedly game changer with Mythos is not the finding, it is chiefly because it can chain these vulns together sequentially to develop exploit chains and is creative/innovative in doing so. Anthropic claims Mythos can also be used to provide FIXES as well, I am not convinced about that. I believe it will FIND more than it can FIX. But even if it can FIND and FIX at the same rate, which it can’t, there is a whole other aspect that is being overlooked. How long it takes to get these FIXES deployed. Even if it can fix all of them it takes time to get these patches into the software upstream because they have to be accepted and TESTED and there is an entire approval process and release process. It’s not instantaneous. Typically a patch takes days even weeks to move through the upstream ecosystem before it becomes available to the general public. Here is the AI generated timescales for a critical vuln: Upstream Fix: 24–48 hours after confirmation by the core project team. Downstream Packaging 12–48 hours for major distros (Ubuntu LTS, RHEL, Debian Stable) to backport and test. Availability to User: 2–5 days from the initial public disclosure of the vulnerability. For arguments sake lets assume we shrink that down to a day. Magically. Then the end users themselves must take these patches and apply them to their infrastructure. This requires another QA cycle at least. These stats are AI generated YMMV: but for Log4J, by Day 10: On average, organizations had patched only 45% of their vulnerable cloud resources. Average Remediation Time: For systems that were detected and tracked, the average time to remediate was 17 days. Priority Patching: Externally-facing systems (those most at risk) were patched faster, averaging about 12 days, while internal systems lagged behind. The 1-Year Mark: By late 2022, telemetry from security firms like Tenable showed that 72% of organizations still had at least one vulnerable Log4j instance in their environment. The U.S. Department of Homeland Security's Cyber Safety Review Board (CSRB) stated that Log4j is a "endemic vulnerability" and predicted it will take a decade or longer to fully eliminate it from the global software supply chain. A DECADE!!

So there is a massive timing problem even if FIND to FIX rate is the same which it won’t be, the entire downstream system cannot move at the right speed to get the fixes deployed into the infrastructure. This all sucks up developer time and cost as teams pivot to emergency mode etc. It’s just a scary prospect.

This is what we are facing. Please can you make suggestions in terms of what you are planning on doing to find and apply patches faster, so that we can get some creative ideas around best practices. We have other things we are doing that solves some of these issues but the speed timing issue is the one that is being overlooked in this entire debate.

Russ from RapidFort