Todd Sundsted

RE: mastodon.social/users/bagder/s

This is a very interesting thread! According to @bagder

  • None of these used Mythos
  • LLMs/AI are driving these vulnerability findings
  • Many of them have been in the code a very long time

The current situation is overwhelming.

If you use curl (or free software in general) consider supporting developers while they work through the tidalwave. I use curl and just sent my support. You should too!

daniel:// stenberg://

not even half-way through this #curl release cycle we are already at 11 confirmed vulnerabilities - and there are three left in the queue to assess and new reports keep arriving at a pace of more than one/day

11 CVEs announced in a single release is our record from 2016 after the first-ever security audit (by Cure 53).