| ▲ | aleksejs 13 hours ago | |
> If you go looking for the public record of what Mythos actually found you land on roughly 40 CVEs, and 28 of those are Firefox and 9 of them are wolfSSL. A browser and a cryptography library. There’s no PHP in that list, no CMS, nothing that resembles the web most people actually use. How does one arrive at the idea that "browsers" is a category less representative of "the web most people actually use" than "PHP applications"? | ||
| ▲ | patrikgrobs 12 hours ago | parent | next [-] | |
Anthropic's own criterion, from the Glasswing page: "systems that represent a very large portion of the world's shared cyberattack surface." A Firefox exploit would be targeted, one user at a time, and you still need delivery. A pre-auth RCE in the CMS behind 40% of the web does fit that criteria better right? | ||
| ▲ | bluGill 12 hours ago | parent | prev [-] | |
You need both sides for a useful web. In this discussion if the servers are all dead web is dead too: don't use a compromised server even if you can't tell it is compromised. | ||