Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Stanislav Fort

๐Ÿ‘ค Speaker
180 total appearances

Appearances Over Time

Podcast Appearances

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

QUIC pin public key bypass.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

CVE 2025-14017.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Threaded IDAPS TLS options broken.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

CVE 2025-1 for 819.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

OpenSSL partial chain store policy bypass.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

In the CURL 8.18.0 release January 8, 2026, we were in fact responsible for three of the six CVEs disclosed and fixed.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

After initial HackerOne reports, we moved to direct private communication with the Curl security team, reporting over 30 additional issues, the majority of which were valid, true positive security issues, 24 Curl PRS now include some variant of reported by.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Stanislav fought as a result.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

In October 2025, Daniel Stenberg wrote a new breed of analyzers acknowledging that some AI-driven security research was producing genuinely valuable results.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

He explicitly mentioned AI-drive discovery.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

As we started to plow through the huge list of issues from Joshua, we received yet another security report against Curl.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

This time by Stanislav Fortfromile, using their own AI-powered tooling and pipeline for code analysis.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Getting security reports is not uncommon for us, we tend to get two to three every week, but on September 23rd we got another one we could confirm was a real vulnerability.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Again, an AI-powered analysis tool had been used.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

End quote.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

In his Curl 2025 year in review, under AI improvements, Daniel Stenberg even wrote directly.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

Quote.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

A new breed of AI-powered high-quality code analyzers, primarily ZeroPath and I'll Research, started pouring in bug reports to us with potential defects.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

We have fixed several hundred bugs as a direct result of those reports.

LessWrong (Curated & Popular)
"AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort

So far.