semisol
· 2w
About this entire AI security scanning thing:
1. Why are people using $ spent as a metric?
2. A huge chunk of these vulnerabilities are likely hallucinated and/or overstated
3. You can’t just point...
$ spent is also the metric is useful when comparing to security audits and bug bounty programs (sadly already a low bar)
overstated or exagerating the impact of bugs are a thing for sure, it is still a useful tool to use can be useful as a starting point. But requires a human to verify vulns and give it a real cve rating
Third point is absolutely right, but you can train the modela and give the harness the right tooling to do the job of a team of junior vulnerability researchers
* just my 2 sats trying to use the clankers for bug hunting during the react2shell and shai-hulud disclosures