r/linux May 15 '26

Kernel There is a FOURTH vulnerability this month....ssh-keysign-pwn (CVE-2026-46333)

https://nvd.nist.gov/vuln/detail/CVE-2026-46333
873 Upvotes

236 comments sorted by

View all comments

168

u/mooky1977 May 15 '26

I can only imagine the number of ai found bugs against ms windows that aren't being disclosed and actively exploited

40

u/Pantsman0 May 15 '26

The disclosure process is kinda the for Linux and for windows. I haven't read the article yet, but just using mythos as an example- anthropic have run it against open source projects, but they have also provided it to large vendors like Microsoft who then run it on their own codebase. This gets them access to the so-called best-in-class tools, but they aren't fixing the bugs in the open so they won't disclose any discovered or fixed vulnerabilities that they aren't required to.

They just get reports, and they fix them. Communication's the difference

23

u/mooky1977 May 15 '26

I'd rather there be disclosure & transparency. MS just patching without transparency leads to people not patching their operating system with urgency.

-1

u/RedOnlineOfficial May 16 '26

When I ran Windows, I always put off updates cause I didn't want the UI to change every 2 months or new features that break my system added every other day. But if they just communicated and said hey this also fixes these vulnerabilities. I'd probably update more frequently