The problem is that "cybersecurity" isn't some special task that only your security team does.
In the project I maintain, I find bugs and fix bugs. Some of those bugs might result in an LPE. I generate a regression test, then I fix the bug.
The problem is that generating a regression test for that type of bug is technically a PoC. I can almost never get Fable to create one. Sometimes Opus 5 punts as well. Same with Sol and Luna.
That is, unless I socially engineer the model. I can't talk about security. I make sure they don't read the file call cve_test.c (literal regression tests for CVEs). I have to hide part of my project from the models for them to work.
Anthropic and OpenAI are driving me to use other models.
Agree 100%. This is just another level of obscurity. Security through obscurity... Its annoying, very annoying.