|
|
|
|
|
by MattSayar
31 days ago
|
|
> The loudest reaction to Mythos Preview from other security leaders has been about speed - scan faster, patch faster, compress the response cycle. More than one team we have spoken with is now operating under a two-hour SLA from CVE release to patch in production [...] If regression testing takes a day, you cannot get to a two-hour SLA without skipping it, and the bugs you ship when you skip regression testing tend to be worse than the bugs you were trying to patch. Over time, I wonder if these models will be able to generate more secure code by default by doing this kind of exploitability testing before ever merging their code. |
|