When it comes to open source software, the corporates funded with state money who want to find vulnerabilities in your software for their advantage are often far more qualified, resourceful and committed to their objectives than the limited project developers are.
You must be more cautious about having both a secure design and a secure implementation of the design of your software at the earliest possible stage of software development. This increases the time and effort to discover a vulnerability or can close out entire classes of vulnerabilities. We have seen how massive projects are weighted down from development standards of the late 90s and 00s that makes them have thousands of CVEs every release.
https://www.phoronix.com/news/Linux-Kernel-CVEs-Nearly-2000
Check out some of the open-source AI tooling from Cellebrite to improve their workflows and automate in researching mobile device vulnerabilities.
You can have opinions on the issues of LLMs (and I have several), but that comes with having to accept an adversary is accelerating how to harm you with that technology.
View quoted note →
GitHub
GitHub - cellebrite-labs/ghidra-rpc: A Ghidra agentic reverse engineering skill.
A Ghidra agentic reverse engineering skill. Contribute to cellebrite-labs/ghidra-rpc development by creating an account on GitHub.
GitHub
GitHub - cellebrite-labs/ida-bridge: Bridge between agents and IDA Pro.
Bridge between agents and IDA Pro. Contribute to cellebrite-labs/ida-bridge development by creating an account on GitHub.
GitHub
GitHub - cellebrite-labs/ida-docs: Agent skill for IDA 9.x IDAPython lookup, backed by the public Hex-Rays IDA SDK.
Agent skill for IDA 9.x IDAPython lookup, backed by the public Hex-Rays IDA SDK. - cellebrite-labs/ida-docs
GitHub
GitHub - cellebrite-labs/ida-porter: Let the agent carry your IDAPython to the next IDA version.
Let the agent carry your IDAPython to the next IDA version. - cellebrite-labs/ida-porter