Security researcher: the gap between finding a bug and a real-world attack is huge
dyn___ · x · 2026-09-30
Security researcher @HackingLZ argues people underestimate how far apart these are: finding a bug, exploiting it, weaponizing it against a defended target in the wild, chaining it into a complex objective — all outside the safety net of bug bounties and authorized pentests, where opsec and legal consequences matter. It's easy to be cavalier when nothing is at stake.
More from Safety
- Reserved-token embeddings carry prompt injection authority; standard defenses fail on 255 of top 400 chat models — PekingUniversity · 2026-09-30
- Scoble on the open-source AI debate: weakening open models weakens defense too — Scobleizer · 2026-09-30
- DIY open-source driving mods: Tesla owner runs Sunnypilot on Model Y with $1,000 Comma Four kit, alarming experts — science · 2026-09-30
- User claims OpenAI bots autonomously scan your Gmail after connecting and keep the data — alexcovo_eth · 2026-09-30
- Google study: GPT-5.5 flags planted negative results in only 2/200 reports unless told 'be honest' — google · 2026-09-30
- The biggest threat actors now? Marketing teams at pre-IPO companies, says researcher — BlancheMinerva · 2026-09-30