
Can open source models be useful in cybersecurity? A few months ago, with the help of AI I discovered that my old TV was susceptible to a Linux bug, CVE-2012-5958, and I used that to hack the TV. The catch? I'm now using Deepseek V4 Pro to see if open source models are capable of finding the exact same bug, because the earlier closed models I used for this research now blatantly refuse to work on my own codebase. In this video I share the short story behind the TV, a brief look at the bug itself, and why we should actually care about this increase in capabilities -- because this same bug could be present in more than just televisions, like routers, cameras, and possibly even medical devices running that version of Linux. DeepSeek has not quite cracked the case yet, however, I suspect that may be a harness / tooling issue rather than a model capability issue as the model was able to autonomously test the capabilities of the TV for over an hour with minimal input required from my end, which shows me it's clearly capable, it just needs to be steered correctly. So, are open source models useful in cybersecurity? Increasingly yes, in just a short amount of time they went from ok to autonomous research over the span of hours. These capabilities will only increase over time, and it's important we address it. This puts the same tools in the hands of the people defending their own devices (as we don't need to be reliant on just the big labs for this). Also next time, I'll have a better camera!
Post summary
The user reports a personal discovery of a Linux bug (CVE-2012-5958) in a TV using AI tools, but no exploit code, patch info, or technical details are provided, leaving it a general discussion.

