we had a backlog of CISA KEV tickets that have piled up. My biggest pet peeve is finding pages and PAGES of entries for a CVE in which 90% of the results are just regurgitating exactly what is on cve.org or the NIST website with absolutely zero insight, or in this day and age of dogshit worthless AI, inputting an exploit template for the vulnerability class mentioned in the CVE, but it is no way relevant to the information I need. Fuckin worse than useless, you copy/pasted from cve.org, and let your AI shit whatever the fuck it wanted on to the page, then just auto-published it.
I hope when the AI bubble collapses, your company goes with it.
@da_667 the latest major ai breach where the gymkana based ai broke loose and hacked hugging face was the most costly breach in history (when coupled with china stepping up excellent open source pressure) #speculative value lost #financial system saved by china #ALE
I need to know more details for CVE-2024-11667
search indexer results: pages and fucking PAGES of omg, its a directory traversal, and OMG, a ransomware group used it
"okay, where is the proof of concept? the exploit details?"
every link, every. single. one: fuck you, that's where.
it was never fun doing this, but AI has made this process infinitely worse. some companies make AI generated videos, which are equally worthless.
@da_667 I found an alleged PoC on github, but I don’t have a device to verify it’s not just some bs: https://github.com/fankh/vulnerability-poc/tree/main/2024/CVE-2024-11667
@schrotthaufen wait. no I got the right CVE number, but that NSE script seems to be testing for an XSS payload.
@buherator @schrotthaufen I'm convinced that the py script is also AI slop. There are no parameters mentioned, nothing.
@da_667 fwiw, its something where CISA KEV is very meeeh, insert dog "no research! just patch!" meme here. And its an EITW claim, not a POC-available claim, kinda makes sense not to request too many details if your goal is getting buy-in from the private sector & SeCuRiTy vendors?
@nyanbinary all I want is to write suricata rules that I can tag as CISA_KEV for rules that cover CISA_KEV vulns. to do that, I need details. I'm fine with closing the ticket, especially if the vuln is more than two years old. At this point, a proof of concept isn't coming.
@nyanbinary they don't want me to do my job? I won't do my job. I get paid either way. Just feelsbadman.
@da_667 can always do what the advisories says 
@da_667 @buherator Oh yeah. I wasn’t logged in, and missed the Claude banner -.-
Edit: The whole fucking repo is just Claude making shit up