Claude wrote a full FreeBSD remote kernel RCE with root shell
91–100 of 128 posts
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#92Earlier quoted context omitted.
> get it pumping out CVEs. Is that a good thing or bad? I see that as a very good thing. Because you can now inexpensively find those CVEs and fix them. Previously, finding CVEs was very expensive. That meant only bad actors had the incentive to look for them, since they were the ones who could profit from the effort. Now that CVEs can be found much more cheaply, people without a profit motive can discover them as we…
It's good and bad. Not all CVEs are the same, some aren't important. So it really depends on what gets founds as a CVE. The bad part is you risk a flood a CVEs that don't matter (or have already been reported). > That meant only bad actors had the incentive to look for them Nah. Lot's of people look for CVEs. It's good resume fodder. In fact, it's already somewhat of a problem that people will look for and report CVE…
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#93Earlier quoted context omitted.
It's good and bad. Not all CVEs are the same, some aren't important. So it really depends on what gets founds as a CVE. The bad part is you risk a flood a CVEs that don't matter (or have already been reported). > That meant only bad actors had the incentive to look for them Nah. Lot's of people look for CVEs. It's good resume fodder. In fact, it's already somewhat of a problem that people will look for and report CVE…
It also depends on if the CVEs can be fixed by LLMs too. If they can find and fix them, then it's very good.
There are some extreme cases that might require extensive code changes, and those would benefit from LLMs. But a lot of the issues are things like off by one issues with pointers.
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#94Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#95Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#96Key point is that Claude did not find the bug it exploits. It was given the CVE writeup[1] and was asked to write a program that could exploit the bug. That said, given how things are I wouldn't be surprised if you could let Claude or similar have a go at the source code of the kernel or core services, armed with some VMs for the try-fail iteration, and get it pumping out CVEs. If not now, then surely not in a too di…
> get it pumping out CVEs. Is that a good thing or bad? I see that as a very good thing. Because you can now inexpensively find those CVEs and fix them. Previously, finding CVEs was very expensive. That meant only bad actors had the incentive to look for them, since they were the ones who could profit from the effort. Now that CVEs can be found much more cheaply, people without a profit motive can discover them as we…
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#97Earlier quoted context omitted.
Claude is already able to find CVEs on expert level. Does it fix them as fast as it finds them? Bonus if it adds snarky code comments
I'm more interested if it fixes CVEs faster than it introduces them.
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#98Key point is that Claude did not find the bug it exploits. It was given the CVE writeup[1] and was asked to write a program that could exploit the bug. That said, given how things are I wouldn't be surprised if you could let Claude or similar have a go at the source code of the kernel or core services, armed with some VMs for the try-fail iteration, and get it pumping out CVEs. If not now, then surely not in a too di…
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#99Key point is that Claude did not find the bug it exploits. It was given the CVE writeup[1] and was asked to write a program that could exploit the bug. That said, given how things are I wouldn't be surprised if you could let Claude or similar have a go at the source code of the kernel or core services, armed with some VMs for the try-fail iteration, and get it pumping out CVEs. If not now, then surely not in a too di…
They tried. It didn't work that well: https://red.anthropic.com/2026/zero-days/
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#100Key point is that Claude did not find the bug it exploits. It was given the CVE writeup[1] and was asked to write a program that could exploit the bug. That said, given how things are I wouldn't be surprised if you could let Claude or similar have a go at the source code of the kernel or core services, armed with some VMs for the try-fail iteration, and get it pumping out CVEs. If not now, then surely not in a too di…
They tried. It didn't work that well: https://red.anthropic.com/2026/zero-days/