5,208 karma · joined June 23, 2017
In "Common mistakes" this article first says not to add this record if you're not actually planning to sell the domain, then says that the record doesn't oblige anyone to do anything, that feels quite weird to me.
And nowhere did I say that those RCEs were in critical software, I'm not talking about the likes of Apache, Nginx, Django, etc.
https://huggingface.co/blog/security-incident-july-2026
> When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on zai-org/GLM-5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.
It sounds absurd, but in the last few weeks I've had a few cases where Sol found an RCE in self-hosted web applications in literal minutes just from reading the code (I prefer when it tries to reason statically instead of spamming runtime probes at first).
In another case it found an arbitrary file write in multiplayer in an old game by reverse engineering the binary - any other player in a match could just send you files to anywhere on your system.
I do these things for pure entertainment and curiosity, not for money from bug bounties, so if Sol can find those with a trivial prompt in tens of minutes for me, then what can focused companies/actors find in days or weeks?
Although I think most vulnerabilities are going to be closed in popular software by mid 2027, except in niche old or abandoned projects.
It's baffling that people would rather call BS on me than try the actual tool being talked about.
It's baffling to me how people are so dismissive of Pangram despite never using it, extrapolating their experience from GPTZero or something else.
You're in for a nice surprise.
And, to be fair, short texts are one of the areas where even Pangram struggles, with a longer text it would be able to identify it as a mix of human and AI written text. They clearly disclose that short text detection is less reliable.
I do understand that some still prefer browsers with JS disabled, but a website could probably detect this and default to in-browser processing, while reserving server-side to those edge cases.