Twelve new vulnerabilities in X.Org Server and XWayland, uncovered by Trend Micro’s Zero Day Initiative with the help of AI, are fixed in xorg-server 21.1.25 and xwayland 24.1.14.
Twelve new vulnerabilities in X.Org Server and XWayland, uncovered by Trend Micro’s Zero Day Initiative with the help of AI, are fixed in xorg-server 21.1.25 and xwayland 24.1.14.
So, how many of those are actually real?
All of these, presumably. The question is how many issue reports the maintainers of those two projects had to wade through to find those relevant twelve. And whether that took more work than they would have had to expend to find those bugs themselves or not.
Twelve of them.
As much as I advocate for human written code, we should also acknowledge that AI has gotten way more competent recently, esp. on the coding front. I think security and vulnerability scanning, (maybe together with code review?), should be the few valid uses of AI.
(And obviously, the human using the AI should confirm the vulnerabilities themselves first before handing it to the maintainers)
(Oh how cutely innocent you are…)
Also, remember that “AI” means scripts in this context. We’ve used scripts to scan for vulnerabilities for decades. That alone is neither new nor scary.
There are serions issues with AI, including how you define it, but scanning code for weak points itself, on its own, is not one. It’s what you do with that data that matters.
Yes, but ai gives a lot of false positives. And when you see articles like this its hard to know if its a verified vurnebility or a potential vurnebility.
It was kind of the same with the old vurnebility test tools
Exactly.
AI is bad at a lot of things, but bug hunting isn’t one of them. It still requires an expert human to be effective but it lets them review a lot more code.