AIs Compress Exploit Timeline
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.
What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.
Simon Willison comments:
Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe.
Subscribe to comments on this entry
r • September 10, 2026 8:17 AM
https://news.ycombinator.com/item?id=49626429
“playing whack-a-mole is losing”
and
this took me a bit to find from 2 days ago i didn’t bookmark it:
https://news.ycombinator.com/item?id=49605691
mildly NSFW?
“we have a year to fix security everywhere”
Not sure i should say this next thing, but what we could be witnessing is the embargoe of exploits by the TLAs to enable attacks elsewhere.
the exploit against chromes sandbox smells a little funny to me, but i didn’t look to see HOW complex the vulnerability really was.