Twelve new vulnerabilities in X.Org Server and XWayland, uncovered by Trend Micro’s Zero Day Initiative with the help of AI, are fixed in xorg-server 21.1.25 and xwayland 24.1.14.

    • xxce2AAb@feddit.dk
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      1 day ago

      All of these, presumably. The question is how many issue reports the maintainers of those two projects had to wade through to find those relevant twelve. And whether that took more work than they would have had to expend to find those bugs themselves or not.

    • 42yeah@eviltoast.org
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      2
      ·
      2 days ago

      As much as I advocate for human written code, we should also acknowledge that AI has gotten way more competent recently, esp. on the coding front. I think security and vulnerability scanning, (maybe together with code review?), should be the few valid uses of AI.

    • fodor@lemmy.zip
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      2
      ·
      2 days ago

      Also, remember that “AI” means scripts in this context. We’ve used scripts to scan for vulnerabilities for decades. That alone is neither new nor scary.

      There are serions issues with AI, including how you define it, but scanning code for weak points itself, on its own, is not one. It’s what you do with that data that matters.

      • user_123@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        Yes, but ai gives a lot of false positives. And when you see articles like this its hard to know if its a verified vurnebility or a potential vurnebility.

        It was kind of the same with the old vurnebility test tools

      • FauxLiving@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        2 days ago

        Exactly.

        AI is bad at a lot of things, but bug hunting isn’t one of them. It still requires an expert human to be effective but it lets them review a lot more code.