Aaron Grattafiori explains how LLMs hunt patch variants at scale
dyn___ · x · 2026-10-10
A Three Buddy Problem x Offensive AI Con crossover episode features Umbriel AI's Aaron Grattafiori breaking down the new offensive-security playbook:
- Patch variant analysis with LLMs: turning incomplete-fix hunting into a scalable pipeline
- Vuln apocalypse vs exploit apocalypse: why mass vulnerabilities haven't become mass exploits; triage, verification, reward hacking
- Death of security through obscurity: closed-source binaries and firmware are now within reach; open source becomes a requirement
- Cost asymmetry: offense is cheap, defense is nearly unaffordable
- Rogue agents: sandbox escapes, and the eval-driven loop behind recursive self-improvement
- Can models write vuln-free code; specialized models and Jev-style classifiers
54-minute podcast with full transcript on securityconversations.com.
More from Safety
- LiveOverflow asks why UUID-as-API-key is standard practice but UUID-as-ID is IDOR — rez0__ · 2026-10-10
- Anthropic accused of calling RSP 'commitments' while dodging legal binding force — Miles_Brundage · 2026-10-10
- Insider says real-time AI mass surveillance and profiling is already here — and it's just the tip — Graham_dePenros · 2026-10-10
- 16-Year-Old's Bug Report: 17 Trillion Microsoft Records Exposed, $5k Bounty — rez0__ · 2026-10-10
- Lawyer: OpenAI could legally disclose why it fired 3 safety researchers, 'trust me' isn't required — GarrisonLovely · 2026-10-10
- Paper decodes 315K encrypted reasoning blocks, recovers 367 PII and 182 credentials — DynamicWebPaige · 2026-10-10