Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Stanislav Fort

๐Ÿ‘ค Speaker
180 total appearances

Appearances Over Time

Podcast Appearances

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

In five cases, IELTS AI system directly proposed the patches that were accepted into the official release after a human review from both IELTS and OpenSSL.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Matt Caswell, executive director of the OpenSSL Foundation, said this about the findings.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Quote

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Keeping widely deployed cryptography secure requires tight coordination between maintainers and researchers.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

We appreciate ILE's responsible disclosures and the quality of their engagement across these issues.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

End quote.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Thomas Meraz, the CTO of OpenSSL, said about the newest security release the following.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Quote.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

One of the most important sources of the security of the OpenSSL library and open source projects overall is independent research.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

This release is fixing 12 security issues, all disclosed to us by ILE.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

We appreciate the high quality of the reports and their constructive collaboration with us throughout the remediation.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

End quote.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

The assigned CVEs still don't represent the full picture here.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Some of the most valuable security work happens when vulnerabilities are caught before they ever ship, which is my ultimate goal.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Throughout 2025, IELTS system identified several issues in OpenSSL's development branches and pull requests that were fixed before reaching any release.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Double free in OCSP implementation, PR number 28300.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Caught and fixed before the vulnerable code ever appeared in a release.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Use after free and double free in RSA OAEP label handling, PR number 29707.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Improper duplication of the OAEP label member could lead to UAF and double free when the duplicate is freed.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Crash in BIO underscore sendums RECVMSG with legacy callbacks, PR number 29395.