Urgent.News

What's breaking now, across thousands of outlets.

Tech

Just a rumour of a bug is enough to find a security exploit these days

Just a rumour of a bug is enough to find a security exploit these days Anil Madhavapeddy is a professor of computer science at Cambridge and a core maintainer of the OCaml compiler. In this somewhat alarming post he reports that security issues in OCaml projects are seeing evidence of attempted exploits within minutes of patches being shared for discussion: This normally takes a few days and a…

A professor of computer science at Cambridge has reported that security issues in OCaml projects are being exploited within minutes of patches being shared. Anil Madhavapeddy, the maintainer of the OCaml compiler, noticed automated probes for traversal sequences in public repositories within just ten minutes of a patch being available.

This rapid discovery rate is incompatible with existing open source practices for disclosing new issues. Security disclosure for rclone project has increased dramatically in the last month, with almost 50 security disclosures compared to about 20 over the past ten years. This rapid pace of discovery has caused significant strain on maintainers, with some projects requiring AI tools to triage and provide fixes.

GitHub is now taking longer to assign CVEs, with assignments taking up to four weeks instead of the previous two to three days.

Written by urgent.news from Simon Willison's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at simonwillison.net →

More in Tech

Minha jornada na Tecnologia: do Hardware à Programação

Sempre tive muito interesse por tecnologia, principalmente pela área de hardware e manutenção de computadores. Ao longo do tempo, fui aprendendo cada vez mais sobre montagem, manutenção, limpeza e…

  • Started career with deep interest in hardware and computer maintenance
  • Expanded curiosity to programming through courses in C# basics and advanced
  • Pursuing Information Technology Management at UNICID, studying Python and SQL

US officials backpedal on claims that China hacked government agencies, now say they were targeted

In a freshly edited statement, the Justice Department said Friday that the US Senate, the Federal Reserve, NASA, and others were "among the targets of QTFY," a Chinese spy platform.

  • US officials revised claims about Chinese hacking of government agencies.
  • Agencies like Senate, Fed, NASA targeted by Chinese spy platform QTFY.
  • Justice Department clarified agencies were targets, not victims.

More from Friday 28 August →