937
you are viewing a single comment's thread
view the rest of the comments
[-] ExLisper@lemmy.curiana.net 22 points 1 week ago

I guess it's about copilot scanning the code, submitting PRs, reporting security issues, doing code reviews and such.

Copilot is everywhere and inescapable on any m$ service.

[-] Ladislawgrowlo@lemy.lol 3 points 1 week ago

reporting security issues

Is this not an advantage? If AI can find new security vulnerabilities reliably?

[-] gwl 23 points 1 week ago
[-] jjagaimo@sh.itjust.works 18 points 1 week ago

It often makes up non existent vulnerabilities. I think it was curl getting flooded with fake vulnerability reports which drowns out real reports, esp because it can take time to parse through the code or run the poc

[-] bananabread@lemmy.zip 9 points 1 week ago

Or it could introduce new ones :)

[-] eronth@lemmy.world 3 points 1 week ago

Yeah, but you can have it scan without implementing.

[-] sp3ctr4l@lemmy.dbzer0.com 6 points 1 week ago* (last edited 1 week ago)

Basically anywhere that LLMs are implemented... they are a security vulnerability, for any situation in which they are not sandboxed.

Anything they can interface with?

You can probably trick it or exploit it into doing something unintended or unexpected to anything else it is connected to.

Either that or take advantage of the system that serves as the framework that connects it to other systems.

Theoretically you could use an LLM to do something like come up with more accurate heuristics for identifying malware....

But... they're nowhere near 'intelligent' enough to like, give it a whole code base for some kind of software, and thoroughly make that software 100% secure.

this post was submitted on 17 Feb 2026
937 points (100.0% liked)

Technology

81802 readers
4004 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS