ZeroHour

Source: oss-security

2 stories in the last 7d

Re: Retrospective by 'gpg.fail' authors

GnuPG maintainer Werner Koch responds on oss-security to a gpg.fail retrospective covering 2003-era GnuPG code.

On oss-security, GnuPG lead developer Werner Koch replied to a retrospective published by the gpg.fail authors, citing a December 2003 commit in GnuPG's gettime.c affecting asctimestamp and printf format attributes in util.h. The excerpt contains no new CVE identifiers or exploitation evidence, and appears to revisit long-standing historical GnuPG code paths discussed by the retrospective's authors.

oss-securityupdated · 1h agofirst · 13h agoResearch 9 sources

Re: AI slops from Eve

David Wheeler's oss-security reply argues AI will make attacks far cheaper and more prolific, urging defenders to protect all IT systems, not just critical ones.

David A. Wheeler posted an opinion reply on the oss-security mailing list in a thread titled 'AI slops from Eve'. He agrees critical IT systems need protection but stresses that all systems have always required defense, since many who assumed they would not be attacked were successfully attacked. He predicts AI-enabled attacks will be painful for many over the next few years because AI greatly reduces the cost of attacks. He also notes AI simultaneously helps with finding and fixing issues.

oss-securityupdated · 3d agofirst · 4d agoIndustry 11 sources1