From nobody Wed Apr 1 17:10:40 2026 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4fmBMg4nn7z6Y92f for ; Wed, 01 Apr 2026 17:10:55 +0000 (UTC) (envelope-from yevhenii.kurtov@gmail.com) Received: from mail-yx1-xb132.google.com (mail-yx1-xb132.google.com [IPv6:2607:f8b0:4864:20::b132]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "WR4" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4fmBMf2Gg6z4633 for ; Wed, 01 Apr 2026 17:10:54 +0000 (UTC) (envelope-from yevhenii.kurtov@gmail.com) Authentication-Results: mx1.freebsd.org; dkim=pass header.d=gmail.com header.s=20251104 header.b=aazerIsQ; dmarc=pass (policy=none) header.from=gmail.com; arc=pass ("google.com:s=arc-20240605:i=1"); spf=pass (mx1.freebsd.org: domain of yevhenii.kurtov@gmail.com designates 2607:f8b0:4864:20::b132 as permitted sender) smtp.mailfrom=yevhenii.kurtov@gmail.com Received: by mail-yx1-xb132.google.com with SMTP id 956f58d0204a3-6501c4857b2so7034619d50.3 for ; Wed, 01 Apr 2026 10:10:54 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1775063452; cv=none; d=google.com; s=arc-20240605; b=dYFtsEOppZtiZ30r7plIRg8Dv1DZxFpFiRaQCq+aTFetxQNabHr1r8IBZBUO9qJk4w 2R1C5pMXF3YdrcTxmzeil6x0HJn0e4JVtoWIsaH/HgwLJOBUvUzDS1EGumFi4r+sMTU8 5Z/4wAevfm6LKgHFifyaa8pAZgiEnouyMoKuo4EMifGJkZcY5pifv+6/5RuFisJqTiHf V3kCTdnzIF1PCLp8UdlFn2Sbkx/pxNQNEaflemgAwd43ET94HwQnbimKkj6MIebwzyVG 56U2m6jw+i1hQzy+IGpucR3AUlGqcjOrkL6How5HW9wjjPF+i9lYgtteJO+zQWBQsZ44 yceg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=goCFbwzPnAcKz/vLX4TOd/9lsPjxT8/4GAygAdKazZk=; fh=8X/fzy6oRkinpO/u1+30mH2eQUCHV465yZU8zsG9ReM=; b=GmtTgQ99lyFxUEwxMjuiAVJ/H8bAlP1FbWDHA9iGOv2r5eyMXL4rOF51eiXo02g2uf e4jPjzOFb7xD4/nsh4Yw4ITb8OB/K97qJsk7630jptc8h/XQyjDiWmX7+YbbQfui5O6c 7hji8GD3Twy2cEu8Yq3uVNMUpNtZSeXdDdwIJptCH3xOTv0ZKA2aOHFaU4MnzgqVK0x4 ZxD+AXHmMZku7+lgB5eWxS+8FuVDa80zFp1dkykjf39RbSV84M5NTF8V51Ak0DaHlvS8 DivRbZ5l1KOTgEpqRbECkIv8VC0ExG2x1tj9vFFfIU0+FgloOh2kPOS2HgH4G5dxrDs2 A4HQ==; darn=freebsd.org ARC-Authentication-Results: i=1; mx.google.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1775063452; x=1775668252; darn=freebsd.org; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=goCFbwzPnAcKz/vLX4TOd/9lsPjxT8/4GAygAdKazZk=; b=aazerIsQcyxbVMd/kBXU6kxLezjywWfBNVF2nv/cDptHLczkaLeKtuBs93E5lZbEVa iF2YXLqYhKAYC8jO72kRzfIf0UBwF1TkAUMCRRamvkWQoc5irPOtsHD+JRzq9JNnAsVT LuVAfzuxu5Ic5f3uxOuG9jheeXXq8O3KbrVNH14vy1i9F5maxcQse7YIjLWXq8dWPTJB u8lh46JvAice3HRHrVUP5BIB7/OogHdqs9/4aH4YKKZlOjR6PUGmqjJsu9S+HuITwfk1 8gQheGDYhBN9Qk1ZzUAgsreNsVnbDrt5y1fXYGWyTVnoEAfLF7LwrRAzH3PJ2l3vfOUp B3UA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1775063452; x=1775668252; h=to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=goCFbwzPnAcKz/vLX4TOd/9lsPjxT8/4GAygAdKazZk=; b=iwROgnITJ8Aioxnl7MjQ7kA+WYWJB1jxrlDbdA+YRJAXMW89t6nMa78AEyOq7j+ogi beuD3Bs7psO7Uc4eeuuYksnCrnCboR8/9kJiA2gGMowAXZ/cVHMn44bXtcOBue0ksKUq Op4DoN9ziK3R/P2X61KZZCuMGeeSKEUbzzTOAy21f0MsrMUDW+yWpGbOK9bHBvqujJPo fvfBn2x49ina37bulLCkCJK/voFdCUL8uvgPcgRb8zihYfxiilJdeTNsYsgsL2Mlw3Oc FO2cDRak8SiCKxENWuwj4fI6Lw+wPjWI4GxJqXSHm4wLPPv7aiQw6e2ygk/+Imd7W7Du yPTQ== X-Gm-Message-State: AOJu0YwPZvY6qZsr9m/VoH2QkI0HA+9vtCtVniZkDlctA11GchKb2xf8 A6rufZJG/Zf/ogNwZ2qGUUbbCBTeb8PYNVN+3T30IPqVPl6WHUJd4HTjGTn7RPYw32/j23YSjxi PGoDt614WRiGvR+q3S0To7R4pFoP5cPI0AmZV X-Gm-Gg: ATEYQzwakEYYzou75OQjbUfH74SFAajUW5PeUsBSrDVYLf188RS+MO9CjJjGHIElHRA FiISCKWCLLAZrBxzg4he19Wxmetk6MDVGQ1ZNV2UFt67bVclWhaSwn0gcTip2WplhEJZ3+vJm1h UlvpsHTYDv2TzHmyUXr6SLBQtRzkXgO0ZWWMG8Ikq8pyHsudKN1dSkU7vK2Dp6zOXcWgsoYAe5D vMia5nIPIPaQJlOOIlY5HJTZ6wg8hqZgYULdnMmBagikSknCSrcJg2MB33y9MXEmrSr4q5nEqzP q+j3K5n+R96jX1Lea/RubYlnqxKWa2BNiT6vFGjdNxVlJq5+Zx+pkC2/on52HERvmw== X-Received: by 2002:a53:bb4e:0:b0:64e:8cde:814d with SMTP id 956f58d0204a3-6502fdd2b43mr3311905d50.17.1775063451925; Wed, 01 Apr 2026 10:10:51 -0700 (PDT) List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org MIME-Version: 1.0 From: Yevhenii Kurtov Date: Wed, 1 Apr 2026 18:10:40 +0100 X-Gm-Features: AQROBzDi9iI05sZne9xQECIYV08cIa1Div9Qf9x7XrfZskNP0mBVdhGRgM6ul9U Message-ID: Subject: Blackhat LLMs wake up call? To: freebsd-security@freebsd.org Content-Type: multipart/alternative; boundary="00000000000081813c064e692ad0" X-Spamd-Result: default: False [-4.00 / 15.00]; SUBJECT_ENDS_QUESTION(1.00)[]; ARC_ALLOW(-1.00)[google.com:s=arc-20240605:i=1]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_MEDIUM(-1.00)[-0.999]; NEURAL_HAM_SHORT(-1.00)[-0.997]; DMARC_POLICY_ALLOW(-0.50)[gmail.com,none]; R_DKIM_ALLOW(-0.20)[gmail.com:s=20251104]; R_SPF_ALLOW(-0.20)[+ip6:2607:f8b0:4864::/56:c]; MIME_GOOD(-0.10)[multipart/alternative,text/plain]; RCVD_TLS_LAST(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCPT_COUNT_ONE(0.00)[1]; FREEMAIL_ENVFROM(0.00)[gmail.com]; TAGGED_FROM(0.00)[]; FREEMAIL_FROM(0.00)[gmail.com]; MIME_TRACE(0.00)[0:+,1:+,2:~]; FROM_HAS_DN(0.00)[]; RCVD_COUNT_ONE(0.00)[1]; MISSING_XM_UA(0.00)[]; PREVIOUSLY_DELIVERED(0.00)[freebsd-security@freebsd.org]; TO_DN_NONE(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; DKIM_TRACE(0.00)[gmail.com:+]; MLMMJ_DEST(0.00)[freebsd-security@freebsd.org]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; MID_RHS_MATCH_FROMTLD(0.00)[]; DWL_DNSWL_NONE(0.00)[gmail.com:dkim]; RCVD_IN_DNSWL_NONE(0.00)[2607:f8b0:4864:20::b132:from] X-Rspamd-Queue-Id: 4fmBMf2Gg6z4633 X-Spamd-Bar: --- --00000000000081813c064e692ad0 Content-Type: text/plain; charset="UTF-8" Hi, Given the torrent of infosec news describing the progress LLMs make on the security front I want to ask if there is something very real coming onto us for which we should prepare. Here is my context: https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked - an essay suggesting that security research economics now allows LLM kiddies to produce 0-days. Frontier LLM exploiting RCE in the latest FBSD https://github.com/califio/publications/tree/main/MADBugs/CVE-2026-4747 Presentation from the guy contributed to the above https://www.youtube.com/watch?v=1sd26pWhfmg. Even though he obviously has a bias, he's still probably one of the most informed people on the planet. Best, Yevhenii --00000000000081813c064e692ad0 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hi,=C2=A0

Given the torrent of infosec = news describing the progress LLMs make on the security front I want to ask = if there is something very real coming onto us for which we should prepare.=

Here is my context:=C2=A0

https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is= -cooked - an essay suggesting that security=C2=A0research economics now= allows LLM kiddies to produce 0-days.=C2=A0

Front= ier LLM exploiting RCE in the latest FBSD https://github.com/calif= io/publications/tree/main/MADBugs/CVE-2026-4747

Presentation from the guy contributed to the above https://www.youtube.com/watch?v=3D1sd26= pWhfmg. Even though he obviously has a bias, he's still probably on= e of the most informed people on the planet.=C2=A0


Best,
Yevhenii
--00000000000081813c064e692ad0--