Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Stanislav Fort

๐Ÿ‘ค Speaker
180 total appearances

Appearances Over Time

Podcast Appearances

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

AI found 12 of 12 OpenSSL zero days, while Curl cancelled its bug bounty.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

This is a partial follow-up to I'll Discovered three new OpenSSL vulnerabilities from October 2025.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

TLDR.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

OpenSSL is among the most scrutinized and audited cryptographic libraries on the planet, underpinning encryption for most of the Internet.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

They just announced 12 new zero-day vulnerabilities, meaning previously unknown to maintainers at time of disclosure.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

We at I'll discovered all 12 using our AI system.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

This is a historically unusual count and the first real-world demonstration of AI-based cybersecurity at this scale.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Meanwhile, Curl just cancelled its bug bounty program due to a flood of AI-generated spam, even as we reported five genuine CVEs to them.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

AI is simultaneously collapsing the median, slop, and raising the ceiling real zero days in critical infrastructure.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Heading Background

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

We at ILE have been building an automated AI system for deep cybersecurity discovery and remediation, sometimes operating in bug bounties under the pseudonym Giant and Eater.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Our goal was to turn what used to be an elite, artisanal hacker craft into a repeatable industrial process.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

We do this to secure the software infrastructure of human civilization before strong AI systems become ubiquitous.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Prisaically, we want to make sure we don't get hacked into oblivion the moment they come online.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

No reliable cybersecurity benchmark reaching the desired performance level exists yet.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

We therefore decided to test the performance of our AI system against live targets.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

The clear benefit of this is that for a new, zero-day security vulnerability to be accepted as meriting a CVE, a unique vulnerability identifier, it has to pass an extremely stringent judgment by the long-term maintainers and security team of the project, who are working under many incentives not to do so.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Beyond just finding bugs, the issue must fit within the project's security posture, that is what they consider important enough to warrant a CVE.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

OpenSSL is famously conservative here.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

many reported issues are fixed quietly or rejected entirely.

โ† Previous Page 1 of 9 Next โ†’