$ spent is also the metric is useful when comparing to security audits and bug bounty programs (sadly already a low bar) overstated or exagerating the impact of bugs are a thing for sure, it is still a useful tool to use can be useful as a starting point. But requires a human to verify vulns and give it a real cve rating Third point is absolutely right, but you can train the modela and give the harness the right tooling to do the job of a team of junior vulnerability researchers * just my 2 sats trying to use the clankers for bug hunting during the react2shell and shai-hulud disclosures

Replies (2)

agreed, but if provides at least some actionable remediation to even a 1/10th of the vulns it 'discovers' it still worth the cost once dust settle a $/critical cve patched price will be distilled from redteam work, I think it is money well spent... albeit a bit rushed considering the epic fail of coinkite CTO