| ▲ | z4y5f3 43 minutes ago | |
Apparently they are scanning OSS and popular software at scale and disclosing the vulnerabilities they found: https://cvd.z.ai/ Most of these are under embargo, but it seems there are a lot of CVE here from a wide range of popular software, many considered critical or high. I understand the argument of "people are not actively looking", but isn't the cost for such a scan getting lower by the week, and Anthropic's Project Glasswing is supposed to find them quite a while ago? | ||
| ▲ | SyneRyder 16 minutes ago | parent | next [-] | |
> ... Anthropic's Project Glasswing is supposed to find them quite a while ago? That was my thought too. For all of Anthropic's talk about their "adversaries", it seems Z.AI have been quietly offering fixes for single shot Remote Code Execution flaws in US software (Safari / WebKit) that Apple and Glasswing / Mythos missed, and that Apple would not attribute to GLM. | ||
| ▲ | re-thc a few seconds ago | parent | prev [-] | |
> Anthropic's Project Glasswing is supposed to find them quite a while ago? Someone still has to run it. The analysis and fix could be someone's machine but not committed / published. | ||