← Back to all episodes
August 10, 2026 — #24

The Cost Was the Control

#24 · ~13 min · Curated by Asaf Nakash

0:00 / 0:00
Listen on: Spotify Apple Podcasts Amazon Music YouTube RSS

Stories This Week

Curator's Corner

One system found 14,090 vulnerabilities in open-source software in two months. In January, curl shut down its bug bounty programme because its maintainers could not absorb the flood of AI-generated reports. Those sound like opposite stories, breakthrough and slop. They are the same story: finding a bug got cheap and checking one did not.

We built our defenses on the cost of finding a bug. I don't think we ever said that out loud, but it is what we did. A 55-day patch cycle is not a claim about engineering capacity. It is a bet that serious vulnerabilities arrive slowly enough that 55 days is survivable, and that bet was priced on scarcity.

The easy dismissal is that volume is not quality: more compute, more noise, the same old patterns. PortSwigger closes that exit. James Kettle's system invented ways of confusing web servers that did not previously have names, then proved them against live systems belonging to a bank, a government and an airport. That is not grinding, and the researcher reporting it also documents those same models failing badly at the exploitation itself.

Unit 42 says 92% of its findings fell outside the categories traditional fuzzing owned. Take that with the caveats already stated. It is not proof that machines understand business logic. It does not need to be. The moat may be standing. The price of testing it fell.

📰 Get the full newsletter — every story, every source, every week