Security Vendor's AI Best Practice: Mislabeling RCE as Secure
Just saw this news and couldn't help but say a few more words. Last Wednesday I was chatting with former colleagues from United Imaging about the deployment process for AI-assisted diagnosis. He mentioned a trend: some security vendors are starting to use AI to automatically generate "best practices" documentation and then push it directly to developers. My reaction at the time was that if this stuff hasn't undergone clinical validation—wait, no, security validation—and they dare to release it, they've got some nerve. And sure enough, today I see this case: in Safeguard.sh's Elixir security guide, vulnerabilities like remote code execution were labeled as "secure."
Physix Frontier