home.social

#patching — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #patching, aggregated by home.social.

  1. How Dangerous Is Anthropic’s Mythos AI?

    Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not... schneier.com/blog/archives/202

    #vulnerabilities #Uncategorized #regulation #patching #hacking #laws #LLM #AI

  2. How Dangerous Is Anthropic’s Mythos AI?

    Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not... schneier.com/blog/archives/202

    #vulnerabilities #Uncategorized #regulation #patching #hacking #laws #LLM #AI

  3. How Dangerous Is Anthropic’s Mythos AI?

    Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not... schneier.com/blog/archives/202

    #vulnerabilities #Uncategorized #regulation #patching #hacking #laws #LLM #AI

  4. How Dangerous Is Anthropic’s Mythos AI?

    Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not... schneier.com/blog/archives/202

    #vulnerabilities #Uncategorized #regulation #patching #hacking #laws #LLM #AI

  5. How Dangerous Is Anthropic’s Mythos AI?

    Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not... schneier.com/blog/archives/202

    #vulnerabilities #Uncategorized #regulation #patching #hacking #laws #LLM #AI

  6. OpenAI Unveils Daybreak to Automate Vulnerability Detection and Patching

    Meet Daybreak, a game-changing cybersecurity tool from OpenAI that supercharges vulnerability detection and patching with cutting-edge AI, helping organizations stay one step ahead of attackers and making the world a safer place. By combining AI intelligence with advanced code analysis, Daybreak…

    osintsights.com/openai-unveils

    #VulnerabilityDetection #Patching #ArtificialIntelligence #Cybersecurity #AutomatedThreatResponse

  7. OpenAI Unveils Daybreak to Automate Vulnerability Detection and Patching

    Meet Daybreak, a game-changing cybersecurity tool from OpenAI that supercharges vulnerability detection and patching with cutting-edge AI, helping organizations stay one step ahead of attackers and making the world a safer place. By combining AI intelligence with advanced code analysis, Daybreak…

    osintsights.com/openai-unveils

    #VulnerabilityDetection #Patching #ArtificialIntelligence #Cybersecurity #AutomatedThreatResponse

  8. Security Tip: Can't patch a production system immediately? Consider virtual patching. 🛡️ By deploying WAF rules, IPS signatures, or runtime protection, you can mitigate specific CVE exploits at the network or host level. This buys your team the time needed to test and deploy official vendor patches without leaving the door wide open. Research the latest vulnerabilities and mitigation strategies at cvedatabase.com #InfoSec #CyberSecurity #CVE #Patching

  9. Security Tip: Can't patch a production system immediately? Consider virtual patching. 🛡️ By deploying WAF rules, IPS signatures, or runtime protection, you can mitigate specific CVE exploits at the network or host level. This buys your team the time needed to test and deploy official vendor patches without leaving the door wide open. Research the latest vulnerabilities and mitigation strategies at cvedatabase.com

  10. Security Tip: The race to patch a critical CVE shouldn't lead to a production outage. 🛡️

    Establish a tiered patch management strategy:
    1. Monitor: Track new CVEs via cvedatabase.com
    2. Stage: Deploy patches to a mirror environment first.
    3. Verify: Run automated tests to ensure no regressions.
    4. Deploy: Roll out to production once validated.

    A broken system is just as unavailable as one under attack. #InfoSec #CyberSecurity #CVE #Patching

  11. Security Tip: The race to patch a critical CVE shouldn't lead to a production outage. 🛡️

    Establish a tiered patch management strategy:
    1. Monitor: Track new CVEs via cvedatabase.com
    2. Stage: Deploy patches to a mirror environment first.
    3. Verify: Run automated tests to ensure no regressions.
    4. Deploy: Roll out to production once validated.

    A broken system is just as unavailable as one under attack. #InfoSec #CyberSecurity #CVE #Patching

  12. Security Tip: The race to patch a critical CVE shouldn't lead to a production outage. 🛡️

    Establish a tiered patch management strategy:
    1. Monitor: Track new CVEs via cvedatabase.com
    2. Stage: Deploy patches to a mirror environment first.
    3. Verify: Run automated tests to ensure no regressions.
    4. Deploy: Roll out to production once validated.

    A broken system is just as unavailable as one under attack.

  13. What Anthropic’s Mythos Means for the Future of Cybersecurity

    Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without exp... schneier.com/blog/archives/202

    #vulnerabilities #Uncategorized #cybersecurity #patching #LLM #AI

  14. What Anthropic’s Mythos Means for the Future of Cybersecurity

    Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without exp... schneier.com/blog/archives/202

    #vulnerabilities #Uncategorized #cybersecurity #patching #LLM #AI

  15. What Anthropic’s Mythos Means for the Future of Cybersecurity

    Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without exp... schneier.com/blog/archives/202

    #vulnerabilities #Uncategorized #cybersecurity #patching #LLM #AI

  16. What Anthropic’s Mythos Means for the Future of Cybersecurity

    Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without exp... schneier.com/blog/archives/202

    #vulnerabilities #Uncategorized #cybersecurity #patching #LLM #AI

  17. What Anthropic’s Mythos Means for the Future of Cybersecurity

    Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without exp... schneier.com/blog/archives/202

    #vulnerabilities #Uncategorized #cybersecurity #patching #LLM #AI

  18. Франкенштейн на 30 ГБ RAM: Как мы пересадили мозг Gemma в скелет DeepSeek и сломали Transformers Операционная «Ghetto MLOps»: пер...

    #llm #deepseek #gemma #transformers #huggingface #pytorch #monkey #patching #moe #kaggle #ghetto

    Origin | Interest | Match
  19. You Can’t Patch People

    One of the things I’ve noticed when it comes to IT is how quickly we’re willing to use software to solve people problems. Over my career I’ve seen all manner of crazy solutions to get around people being lazy or uneducated. Remember vMotion? Or OTV for stretched layer 2? Why do you think those solutions came about? I posit that it’s because it’s faster to write software than to patch people.

    Hacking Humans

    I see this most often in cybersecurity. Developers love to create software solutions that prevent things from happening. Phishing and all its various forms are some of the top priorities for solutions that prevent leaking of information. While we have invested a lot in phishing tests and education it’s also very likely that there are controls in place that prevent users from accidentally giving out information to threat actors.

    Why are we so willing to write software to fix problems instead of teaching people to avoid those issues? I think in part it’s because software is predictable. If I create an app or write some controls into a platform it’s going to behave the same way every time. That’s the definition of deterministic. Every time the software is presented with an input it will react the same way. That makes it easy to figure out. People that deal with risk on a daily basis just love predictability.

    Humans are messy. We don’t always behave the same way every time. Even someone that knows they shouldn’t click on links in an email will do it because they aren’t paying attention or because they are tired. When you factor in how much better the phishing emails have gotten thanks to the advent of generative AI even the rank-and-file people are getting tricked. Developers would rather deal with software than trying to send more tests and update education resources.

    The real issue is that we can’t patch people as easily as we can with software. If updating the filters for spam and phishing and other security related items was as simple as downloading the new attack vectors into someone’s brain we’d be doing that instead. Likewise, if we could just convince people to build things a certain way to avoid having to create complicated systems like FHRP we would be doing that instead of trying to solve for lazy developers.

    Treating People Like Programs

    Why is it so hard to patch people? Forget about the deterministic part of the equation for a moment. Software isn’t instantly updated when something is discovered. It takes time to develop lists of new vectors or update programs to remove vulnerabilities. Why can’t we do the same for people and reduce the overhead of all the extra software?

    People can be “patched” with education. It isn’t always easy to get people to take courses or read the bulletins that are sent out. There are ways to force people to do it but that kind of friction just makes security teams resent users for trying to avoid mandatory training updates. Hence the reliance on software to fix the issues. But it doesn’t have to be like that.

    Instead of forcing people to take updated training you could use something like gamification to encourage people to update training or learn about new issues. This is especially good with younger or newer employees that are used to the badge hunt mentality. Giving them the option to display achievements tied to training is a great way to encourage them to keep updated while also pulling others in that want to earn the same recognition.

    Tom’s Take

    I get the desire to rely on deterministic software rather than dealing with unreliable people. But there is only so much software that you can write to try and fix behaviors. We eventually have to get to a point where we can educate users and encourage them to want to keep up with it instead of forcing them to go through endless modules that don’t give them any real info. If we would just put in a bit of the effort we use on software controls into the people we’re trying to restrict we might find the effort is multiplied far beyond what we could hope for.

    #Patching #security
  20. Has anyone got any recommendations for not super difficult to use / setup / manage linux patching solutions? I was looking at Landscape as most of the servers are Ubuntu but it turns out you need "Call us" pricing with Ubuntu Pro to get more than 10 servers installed (And spoiler, I have more than 10 servers just to run Mastodon stuff!).

    #Linux #Patching #Security #DevOPS

  21. Has anyone got any recommendations for not super difficult to use / setup / manage linux patching solutions? I was looking at Landscape as most of the servers are Ubuntu but it turns out you need "Call us" pricing with Ubuntu Pro to get more than 10 servers installed (And spoiler, I have more than 10 servers just to run Mastodon stuff!).

    #Linux #Patching #Security #DevOPS

  22. Has anyone got any recommendations for not super difficult to use / setup / manage linux patching solutions? I was looking at Landscape as most of the servers are Ubuntu but it turns out you need "Call us" pricing with Ubuntu Pro to get more than 10 servers installed (And spoiler, I have more than 10 servers just to run Mastodon stuff!).

    #Linux #Patching #Security #DevOPS

  23. Has anyone got any recommendations for not super difficult to use / setup / manage linux patching solutions? I was looking at Landscape as most of the servers are Ubuntu but it turns out you need "Call us" pricing with Ubuntu Pro to get more than 10 servers installed (And spoiler, I have more than 10 servers just to run Mastodon stuff!).

    #Linux #Patching #Security #DevOPS

  24. Has anyone got any recommendations for not super difficult to use / setup / manage linux patching solutions? I was looking at Landscape as most of the servers are Ubuntu but it turns out you need "Call us" pricing with Ubuntu Pro to get more than 10 servers installed (And spoiler, I have more than 10 servers just to run Mastodon stuff!).

    #Linux #Patching #Security #DevOPS

  25. Cybersecurity in the Age of Instant Software

    AI is rapidly changing how software is written, deployed, and used. Trends point to a future where AIs can write custom software quickly and easily: “instant software.” Taken to an extreme, it might become easier for a user to have an AI write an ... schneier.com/blog/archives/202

    #computersecurity #vulnerabilities #Uncategorized #cybersecurity #patching #LLM #AI

  26. Cybersecurity in the Age of Instant Software

    AI is rapidly changing how software is written, deployed, and used. Trends point to a future where AIs can write custom software quickly and easily: “instant software.” Taken to an extreme, it might become easier for a user to have an AI write an ... schneier.com/blog/archives/202

    #computersecurity #vulnerabilities #Uncategorized #cybersecurity #patching #LLM #AI

  27. Cybersecurity in the Age of Instant Software

    AI is rapidly changing how software is written, deployed, and used. Trends point to a future where AIs can write custom software quickly and easily: “instant software.” Taken to an extreme, it might become easier for a user to have an AI write an ... schneier.com/blog/archives/202

    #computersecurity #vulnerabilities #Uncategorized #cybersecurity #patching #LLM #AI

  28. Cybersecurity in the Age of Instant Software

    AI is rapidly changing how software is written, deployed, and used. Trends point to a future where AIs can write custom software quickly and easily: “instant software.” Taken to an extreme, it might become easier for a user to have an AI write an ... schneier.com/blog/archives/202

    #computersecurity #vulnerabilities #Uncategorized #cybersecurity #patching #LLM #AI

  29. Cybersecurity in the Age of Instant Software

    AI is rapidly changing how software is written, deployed, and used. Trends point to a future where AIs can write custom software quickly and easily: “instant software.” Taken to an extreme, it might become easier for a user to have an AI write an ... schneier.com/blog/archives/202

    #computersecurity #vulnerabilities #Uncategorized #cybersecurity #patching #LLM #AI

  30. #MilpitasCA - #MendWithFriends

    Saturday, April 11, 2026
    11:00AM – 12:30PM

    #MilpitasLibrary
    160 North Main Street
    Milpitas CA 95035

    "Do you have...

    ...a stuffed animal with the stuffing leaking out?

    ...a shirt with a missing button?

    ...a hole you want to patch?

    ...a stain you want to cover up?

    Bring it to the Mend with Friends mending club and let’s fix it together! If you are curious about sewing, we can also introduce beginners to some basic hand-sewing stitches.

    No registration is required; bring your own items to mend, project to work on, or practice basic stitches with our fabric scraps! Limited mending supplies for hand sewing and casual instruction are available, but bringing your own favorite tools, extra buttons, fabric scraps, or experience to share is always appreciated.

    Children are welcome to accompany their caregiver and learn alongside them.

    We meet every month on the second Saturday!"

    FMI:
    sccl.bibliocommons.com/events/

    #SolarPunkSunday #Mending #StuffieRepair #Patching #Stitching #LearningSewing #BuildingCommunity
    #LibrariesRule!

  31. #MilpitasCA - #MendWithFriends

    Saturday, April 11, 2026
    11:00AM – 12:30PM

    #MilpitasLibrary
    160 North Main Street
    Milpitas CA 95035

    "Do you have...

    ...a stuffed animal with the stuffing leaking out?

    ...a shirt with a missing button?

    ...a hole you want to patch?

    ...a stain you want to cover up?

    Bring it to the Mend with Friends mending club and let’s fix it together! If you are curious about sewing, we can also introduce beginners to some basic hand-sewing stitches.

    No registration is required; bring your own items to mend, project to work on, or practice basic stitches with our fabric scraps! Limited mending supplies for hand sewing and casual instruction are available, but bringing your own favorite tools, extra buttons, fabric scraps, or experience to share is always appreciated.

    Children are welcome to accompany their caregiver and learn alongside them.

    We meet every month on the second Saturday!"

    FMI:
    sccl.bibliocommons.com/events/

    #SolarPunkSunday #Mending #StuffieRepair #Patching #Stitching #LearningSewing #BuildingCommunity
    #LibrariesRule!

  32. #MilpitasCA - #MendWithFriends

    Saturday, April 11, 2026
    11:00AM – 12:30PM

    #MilpitasLibrary
    160 North Main Street
    Milpitas CA 95035

    "Do you have...

    ...a stuffed animal with the stuffing leaking out?

    ...a shirt with a missing button?

    ...a hole you want to patch?

    ...a stain you want to cover up?

    Bring it to the Mend with Friends mending club and let’s fix it together! If you are curious about sewing, we can also introduce beginners to some basic hand-sewing stitches.

    No registration is required; bring your own items to mend, project to work on, or practice basic stitches with our fabric scraps! Limited mending supplies for hand sewing and casual instruction are available, but bringing your own favorite tools, extra buttons, fabric scraps, or experience to share is always appreciated.

    Children are welcome to accompany their caregiver and learn alongside them.

    We meet every month on the second Saturday!"

    FMI:
    sccl.bibliocommons.com/events/

    #SolarPunkSunday #Mending #StuffieRepair #Patching #Stitching #LearningSewing #BuildingCommunity
    #LibrariesRule!