Anyone who took this seriously is sitting on thousands of exploits and creds, but they didn’t and so they aren’t. It’s 18 months old at this point. We have since used it to find vulns in MS products and docker images. This is just Nuget…what about npm, PyPi, PowerShell gallery, Brew, Docker, …
github.com/dreadnode/example…
If a leading lab talks like 500 is a big number, it means they don’t have a clue about their own scale wrt cyber.
CVE system is functionally pointless. Vulnerabilities can exist without a CVE, and they already couldn’t keep up. Not only that, but disclosure has become one of the worst experiences as a researcher. So, why bother with either.
someone at ANTHROPIC just showed CLAUDE finding ZERO DAY vulnerabilities in a live conference demo
claude has found zero day in Ghost, 50,000 stars on github, never had a critical security vulnerability in its entire, history...
it found the blind SQL injection in 90 minutes, stole the admin api key, then did the exact, same thing to the linux kernel