this post was submitted on 08 May 2025
91 points (97.9% liked)
Tech
1041 readers
86 users here now
A community for high quality news and discussion around technological advancements and changes
Things that fit:
- New tech releases
- Major tech changes
- Major milestones for tech
- Major tech news such as data breaches, discontinuation
Things that don't fit
- Minor app updates
- Government legislation
- Company news
- Opinion pieces
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Why bother submitting vulnerability reports just because some AI claims one with no POC?
There's a bounty on reported vulnerabilities (meaning money is paid out) and you could get a lot of fame, if you're the security researcher who found something in Curl. When it takes basically zero effort to generate a report and there's a theoretical non-zero chance for the AI to generate a valid report (or at least some people are convinced of that), then you'll have people hoping to make a quick buck.