Most of my job is figuring out what not to touch. We have dependencies in prod from before I started, half the system uses them and nobody has opened them in years. Every audit I just skip past it. You dont wanna be the one who breaks something you didnt even know depended on it. Saw something with GLM-5.3 the other day that kinda proved where these things are actually useful. They ran it over alot of open source, turned up thousands of vulns, bunch of them critical. One had been sitting there since 1981. Longer than I've been alive. Buried in kernels and browsers, stuff nobody rereads. Problem was never finding bugs tho. We were already drowning in the ones we knew about, now theres just more. Piles bigger. But its a pile I know about instead of one sitting in a file I avoid, so I'll take it. submitted by /u/Sinver_Nightingale27 [link] [comments]
The article discusses the use of an AI model (GLM-5.3) to discover 1,097 critical and high-severity vulnerabilities across legacy kernels, browsers, and infrastructure code, including one flaw dating to 1981. The core issue is the identification of deeply buried, unmaintained vulnerabilities in pervasive dependencies that are typically avoided during audits. No specific CVSS scores, affected versions, fixed versions, or workarounds are provided in the source material.