Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Okay, but I mean the initial finders of the vulnerability. If they are conducted manual code reviews, automatic static analyses or fuzzing.


Visit the link in the comment to which you're replying.


I think he is talking about NSO group, or whoever sold it to them. However, obviously that's unlikely to get revealed.


I have to imagine that NSO group just watches the commit log for "I optimized webp" lol it's free CVEs


All of the above.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: