Risky Business Features

How the CopyFail disclosure went sideways

18 min · 21. maj 2026
episode How the CopyFail disclosure went sideways cover

Beskrivelse

In this episode, Theori’s Brian Pak and Andrew Wesie join James Wilson to discuss why the CopyFail exploit was publicly disclosed before Linux distributions had their patches ready. As you’ll hear in this episode, mistakes were made and lessons learned. It’s worth a podcast, too, because in our opinion this incident foreshadows the inevitable problems that open source software will face in the unfolding vulnpocalypse. SHOW NOTES

Kommentarer

0

Vær den første til at kommentere

Tilmeld dig nu og bliv en del af Risky Business Features-fællesskabet!

Kom i gang

2 måneder kun 19 kr.

Derefter 99 kr. / måned · Opsig når som helst.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

Alle episoder

23 episoder

episode Mythos smythos! How to find 0day with lesser models cover

Mythos smythos! How to find 0day with lesser models

In this podcast James Wilson chats with Niels Provos about his research into using older AI models to successfully hunt for 0day vulnerabilities. Niels has had a long and prolific career in cybersecurity, having worked as a Distinguished Engineer at Google and then heading up security at Stripe. His interest in AI bug hunting was piqued recently when one of the Mythos 0day vulnerabilities that received lots of attention happened to be in code he wrote for the OpenBSD project 27 years ago. It got him thinking: Are these frontier models really that magical? Or could we replicate their findings with some clever orchestration instead of relying on the model’s smarts to find bugs with a single prompt? As it turns out, this was worth looking into. Niels’ orchestration framework, Iron Curtain, works extremely well. This episode is also available on YouTube [https://youtu.be/ksWbjE9uQyk] SHOW NOTES * Finding Zero-Days with Any Model [https://www.provos.org/p/finding-zero-days-with-any-model/] * Security Blueprints [https://securityblueprints.io/]

8. maj 20261 h 27 min