Intel Node
The time of much patching is coming
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
In this week’s newsletter, Martin reflects on what the next iteration of AI tools means for vulnerability discovery and our ability to manage large-scale patch releases.
Welcome to this week’s edition of the Threat Source newsletter.   Many solutions have been proposed to reduce software bugs: zero-defect mandates, pair programming, formal methods, and mathematical software proofs. The reality is that software engineering is  hard . Identifying and fixing bugs before they make it into production code is  hard . Source code peer review and extensive unit testing have improved code quality, but bugs still get through.   Not every bug is a vulnerability, and not every fault that appears to be a vulnerability can be usefully exploited.
Nevertheless, through extensive testing and review, a skilled vulnerability researcher can still uncover faults in software that has already undergone rigorous quality assurance.