AIs Compress Exploit Timeline

Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.

What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.

Simon Willison comments:

Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe.

Posted on September 10, 2026 at 6:40 AM22 Comments

Comments

r September 10, 2026 8:17 AM

https://news.ycombinator.com/item?id=49626429

“playing whack-a-mole is losing”

and

this took me a bit to find from 2 days ago i didn’t bookmark it:

https://news.ycombinator.com/item?id=49605691

mildly NSFW?

“we have a year to fix security everywhere”

Not sure i should say this next thing, but what we could be witnessing is the embargoe of exploits by the TLAs to enable attacks elsewhere.

the exploit against chromes sandbox smells a little funny to me, but i didn’t look to see HOW complex the vulnerability really was.

Bernhard Fröhler September 10, 2026 8:26 AM

This is only one of many recent things indicating to me that AI supports bot defenders and attackers equally. From what I’m reading, I don’t see the disadvantage for defenders (having to defend a whole surface vs. attackers only needing to find a single exploitable weakness) going away anytime soon. There might be more security issues fixed than ever before, but attackers also have it much easier to discover and exploit open issues.

Clive Robinson September 10, 2026 9:27 AM

@ r,

With regards,

“Not sure i should say this next thing, but what we could be witnessing is the embargoe of exploits by the TLAs to enable attacks elsewhere.”

This is an issue I’ve been thinking about for some time, as I’ve realised just how fast agenetic attacks can work. They only need a tiny hint to go searching and quickly find, and develope an exploit in considerably less time than the software developers can consider if they should patch or not…

Very few people are thinking it through when it comes to embargoes by TLAs or other Guard Labour.

To avoid it being a “fast track hint” that an AI would produce an attack to probably within minutes…

The embargo message from a TLA would have to be so near to “meaningless” that it would be pointless issuing.

Even if the TLA embargo was only issued to the design team the effect it would have on the design team would be sufficient to “tip-off”.

Consider it to be like “traffic analysis” you do not need to know the contents of an encrypted message you only have to “see the changes” that follow on from it being received.

Rontea September 10, 2026 9:40 AM

When even the rumor of a bug spawns exploit traffic, you know the game has changed. We’re seeing attacker automation move faster than traditional OSS security workflows: a fix PR goes live, and within ten minutes probes are hitting the target. That’s a dangerous inversion of the old disclosure cycle.

We have to stop assuming secrecy buys safety. The future is continuous rollout, lightweight trust networks for coordination, and defensive automation that moves as fast as the attackers do.

KC September 10, 2026 10:37 AM

Anil – a Cambridge prof and maintainer of the OCaml compiler – isn’t the only OSS developer who’s aware of the speed of AI-driven attacks. Simon Willison observes further conversation.

The ‘rumors’ are real. There are automated watchers on public repos, communication platforms (Slack/Discord) are leaky, and merely high-level descriptions allow AI agents to discover exploits.

Per an M-Trends report, the new mean time to exploit vulns is -7 days (yes, negative 7 days).

Anil says that ‘mom and pop’ maintainers don’t yet have access to frontier models for help, adding “if anyone from Project Glasswing is listening, team OCaml could use access now :-)” He is currently using his own Claude and DeepSeek V4 Pro.

Anil outlines several proposals to help the OSS community combat the speed of AI-driven attacks, including private development, continuous shipping, and virtual patching ala commercial CDNs.

No time like now to bring these conversations to the forefront.

lurker September 10, 2026 1:55 PM

@r

From your first link:

“We simply shouldn’t trust software to a job that belongs in hardware.”

Resurrect Charles Babbage. He could make a decent, safe computer with modern technology. And that doesn’t mean with existing chipsets, he would design chips that worked properly. Babbage was a polymath, and right now we need more polymaths. LLMs are not the answer.

Bcs September 10, 2026 2:56 PM

I wonder how deep the pit is? If a project were to just back burner everything but security fixes, how long would they need to grind on that before the models would quit finding exploits faster than the maintenance team can process the fixes?

I know doing that is not practical in the real world, but if the answer is 1-3 years that suggests much different responses than if it’s “not any point in the foreseeable future”.

Clive Robinson September 10, 2026 3:15 PM

@ KC, ALL,

With regards,

“Simon Willison observes further conversation.”

There is nothing in there that I’ve not said on this blog over many years.

I’ve mostly mentioned it in regard to “short term thinking” in management.

That gets handed down by US legislation and Court decisions with regards the supposed rights of “shareholders”.

There was a time when US Corps were run with a longer term view. However two events occured on around a half century ago, the other a third of a century ago.

1, Access to labour at low cost in the Far East etc.
2, The rise of communications with next to no or no “metered” cost.

These enabled the two killers of waged labour,

1, Out Sourcing
2, Off Shoring

All in the name of “shareholder benefit”.

The final nail in the coffin you could say was various US Court decisions where shareholders could take a company to court and strip R&D budgets into shareholder dividends and the like.

Every thing we now see can be traced back to these things and the “short term thinking” they brought forth.

But remember the other point I’ve made in the past,

The future of a company exists not in the vampire shareholders but the customers bringing in income from which all else can happen.

When you outsource and offshore you almost always get rid of “units of work resource” ie people who earn money that they mostly put back into the local economy as “customers” of local businesses who in turn are customers in the local economy.

This goes by various names one of which is “economic churn”. It’s been estimated as a rule of thumb in the past that every 1$ you put into the local economy creates 10$ of local economic activity.

Now consider from a simple perspective what happens when you outsource and off shore 1$ from the local economy into a distant economy in the Far East or other place where labour is only a fraction of the cost.

Well arguably you have a 100:1 effect on what happens to the distant economy to your local economy. It’s not immediately obvious it takes around ten to twenty years but the effect is to drain the local economy and turn it into a “brown field” poisoned swamp… Whilst turning a distant set of paddy fields into a thoroughly modern industrial base using the latest technology with workers who will work long hours because what appears a small income in your local economy due to “purchase power” difference makes it a comparative fortune in the distant economy.

There are related effects that mean that the educational standard goes up significantly in just a couple of generations in the distant economy and in the process raises the global economy education level. Whilst the skills base in the local economy dies out, and the generations coming through do not get the levels of education required to compete in the global economy.

Corporate “short term thinking” driven by the neo-con notion of “share holder value” and using the incurring of debt to extract future value to “not leave money on the table/floor” robs organisations of resilience and R&D with the results you can see all around.

The latest idea is to turn what few customers you have into “renters” on the “never ever principle”. It gets worse when you see what the likes of Broadcom are doing as you could call them “the sea-weed future indicator” and they are showing “major stormy weather by design” ahead.

Clive Robinson September 10, 2026 3:47 PM

@ Keep your problems 2 yoursef,

Every time you squawk you show your utter inadequacies and cognitive failings in life.

Why do you commit such “self abuse” in public?

Do you think the changing of handles and sock puppet behaviour makes you somehow superior or clever?

All it makes you look like is “Violet Elizebeth Bott” throwing a tantrum due to being to inadequate to get her own way,

https://www.youtube.com/watch?v=HXiZHXkG-ac

Clive Robinson September 10, 2026 7:53 PM

@ Bcs, ALL,

With regards,

“I wonder how deep the pit is? If a project were to just back burner everything but security fixes, how long would they need to grind on that before the models would quit finding exploits faster than the maintenance team can process the fixes?”

The answer to both your questions is unfortunately,

“Can not be known but infinite is not impossible.”

There are two reasons that are immediately obvious when you say them,

1, Vulnerabilities that can be exploited suffer from the “unknown unknown” issue of new attacks.
2, All changes to any code base including vulnerability fixes have a probability of introducing new vulnerabilities, thus new attacks.

Also I’m fairly certain that not all ways of converting vulnerabilities into working attacks are known to the weights in the DNNs of the LLMs.

The fact that the attacks get more numerous after the ML component of a “Current AI System” has been run again or the LLM has been updated in other ways tends to point to the fact that it’s a “work in progress”.

And that’s all before LLMs being used to Attack rather than Defend,

1, Find new instances in currently known classes of attack.
2, Find new instances close into current classes of attack that can be classed as a new class of attack.

That is the way the stochastic process works in an Current AI LLM System is that it “gap fills” between known instances by

“Slowly growing outwards by trial and checking.”

It only appears “fast” due to the indefatigable agents that can run in the many thousands simultaneously as the task is highly parallelizable.

And this is the real danger, not that it can attack, but just how many attempted attacks can be run at the same time untill a working one is found.

But the real sting in the tail as it were is that the Agentic Systems have the apparently easy capability to chain vast numbers of partial attacks into a full working attack…

Humans have not really done this in the past, because they usually can see ways to more easily build quite short chains that work.

In a way this is bringing new attacks from old partial vulnerabilities that we had not considered, thus have not yet defended against.

But further consider,

“The Xmas Gift that keeps Giving”

Of the CPU “go faster stripes” that gave us Spectre and Meltdown and all their successors. We’ve yet to see LLMs be used against the hardware internal vulnerabilities.

So I suspect there are many years of milage left in LLM conversion of vulnerabilities into working attacks.

So your observation of,

“not any point in the foreseeable future”

Is likely to be true…

r September 10, 2026 7:53 PM

i have serious blood pressure issues too, things have side effects. harassing people online can lead to /compound/ interst in reality.

“harmless fun”, like many school-yard bullies hide behind can escalate quickly. they’re called ‘vulnerable’ populations for a reason.

something curious, immediately after posting my above comment my phone went into a suppressive screen turn-off/disable loop.

Clive Robinson September 10, 2026 9:41 PM

@ r,

I’m sorry to hear you have medical issues as at the very least the make you feel less than 100%.

Hypertension issues can “hide away for years” slowly causing harm, and hypotension issues can be alarming as they can give rise to blurred/tunnel vision, tinitus and for some Syncopy (passing out of the stand take three steps and drop variety). Hence you are often nolonger allowed to operate machinery, drive vehicles or even have a job as you represent a danger to others who might come to your aid…

And also the all to often “the drugs don’t work” or worse “cause problems of their own” and I’ve found out through basic research that the medical profession are often not to observant of those under their supposed care…

I can give a list of over ten drugs that are just prescribed but not followed up sufficiently with Statins being #1 on the list[1].

But the one that concerns me most at the moment are the GLP-1 antagonists. Of those actually prescribed the medication as part of diabetic control or to reduce effects in heart failure, around 10% have gastrointestinal issues that need to be closely monitored as they can cause all sorts of nasties including “Acute Kidney Injury”(AKI) which can easily become life threatening. And likewise pancreatitis that can be quite life threatening [2].

Now consider all those “housewife-types” that get hooky prescriptions so they can loose weight and still “lunch”… There are already reports about both short term and longterm use issues, and even that they effectively stop working so larger doses get given… And that’s for the genuine GPL-1 drugs, unfortunately there are many fakes out there now that use insulin to fake or pad out the effects.

It’s the sort of thing that can easily turn into a significant issue in a couple of years or so.

Look up a drug called Gliclazide it was likewise a Type II Diabetic Drug once “also prescribed to help the morbidly obese loose weight”… Thus others who were only just somewhat over weight… And that was when the pancreatitis issue raised it’s ugly head and became a bit of a national scandal in the UK[3].

So it’s not as though these GLP-1 antagonist drugs are not following a well trod path…

Any way my advise if a doctor suggests a new medication is you look up the “Patient Notes” then look it up in BNF etc and have a search in Medline to see what comes up. Mostly what you will see will be understandable.

But “For Gawds Sake” do not ask AI, as it will almost certainly give you incorrect or incomplete information.

[1] Statins are one of those drugs that are pushed in ways you will find in the “Dammed Lies and Statistics” book. Thus some say their efficacy is dubious. What is not dubious is the 10% of users who have acute muscular skeletal issues because of them,

‘https://scitechdaily.com/scientists-finally-crack-decades-old-mystery-behind-statins-painful-side-effects/

[2] It’s becoming of UK national concern as well,

‘https://www.gov.uk/government/news/if-you-take-a-glp-1-medicine-and-have-been-hospitalised-by-acute-pancreatitis-the-yellow-card-biobank-wants-to-hear-from-you

[3] The pancreatitis issue connected with Gliclazide was clear in scientific research literature, but had not made it through to doctors or most of the medical profession… Shortly before the scandal hit the MSM I’d upset my then Doctor who was insisting I try it, and he got really upset when I flatly refused and told him why. He demanded that I tell him who had been telling me such things and as I pointed out I could read published science papers just like anyone else could and that he really should do so, rather than berating patients for excercising their rights to refuse medications they had good reason to believe might be harmful.

Clive Robinson September 11, 2026 4:09 AM

@ I’m coming “clive”

Is that because as previously noted

Why do you commit such “self abuse” in public?

It is after all what you keep claiming you are upto…

But now you are running around like a headless chicken flapping, impotent and incapable of even just rational thinking.

You claim,

“A basic rule in English language…”

But Let’s look at your starting handle that you began all your nonsense with,

“Keep your problems 2 yoursef”

Do you not see your deficiency?

It’s known to some professions as “a tell”…

It’s one we have seen here before from postings long ago, where complaint was also made specifically about “to and too”.

So you got tested and as others have noted you walked right into the trap. So here you are pulled up by your own failings.

And for those that remember back then it was a name claimed as genuine as a handle… And because of the behaviour exhibited under it, it got banned.

Yes, the host of this blog actually said at the time we were not to use that name again.

As the behaviour exhibited by the poster of going completely nuts when people quite legitimately called the posts made under it fraudulent. So in deference to our hosts wishes I won’t say it.

But anyone that has been upset previously, now, or even in the future, by such posts now knows how to find out who it was back then.

Oh and the fraud back then, as you are now, was trying very unsuccessfully to fake “expertise” and significantly failing.

All can see you are “going nuts” in such a way, so they can draw certain conclusions from that. Likewise your days and times of posting suggest the “Dutch Courage” of an embittered drunk raging against their self inflicted fate, whilst trying to eke out an existence in “bottom of the socioeconomic lader” low payed work.

Is it manual labour, in a demeaning and humiliating service position?

Such as a job as a “groceries check out bag filler” or similar? That used to be portrayed by US Media world wide as work released convicts aspire to.

Hmm the repeated connection you make with what you claim are “criminals” will no doubt make some wonder if you’ve been arrested, convicted, and done time…

So I guess you are going to miss out on that $5000 voting bribe it is being said in the media that the Trumper is going to give registered voters if he gets both houses at the upcoming mid-terms.

How does that being left out thinking feel? Especially as you must know it’s your own inadequacy that is the cause…

r September 11, 2026 8:13 AM

@lurker,

the dyson /fear/

does all biological life automate itself into truncation?

if this is a simulation to see if biological life with a headstart can overcome silicon germanium and carbon nanotubes, then we may have to lose to win THAT reality.

@clive,

thanks for the medical info, I’ve been mulling my prescriptions lately because iirc one of them causes charlie horses. I have an optician it’s watched fervently, but it’s a mountain out of a molehill. I planned to investigate last night but I think the dept. of homeostasis intervened (I don’t believe in co-incidents)

as a side note, Samsung must have quietly dropped their clipboard mngmt, I’ll have to investigate.

Kris September 12, 2026 3:00 AM

well – AI is changing approach to many security maintenance activities. Patching or vulnerability management on specific cadences does not make sense – it must be continous and must be real time. Otherwise it does not make any sense

Clive Robinson September 12, 2026 7:23 AM

@ faux-Anonymous,

With regards,

“just who the fk u think u r…”

Well as others have noted easily able to walk into a trap…

Also determine quite accurately –judging by your near mindless, incoherent response– your caliber as a person, your questionable past, lack of socioeconomic standing, oh and your abuse of chemical substances.

Any other of your failings I’ve not listed I’m sure most others can easily work out for themselves, especially your predilection for male flesh in “Not Suitable For Work”(NSFW) usage.

All suggesting you lack any social or romantic associations in what passes for your social/private life, and likewise are probably shunned / derided in public / work spaces and the like…

Jimmy September 12, 2026 11:45 PM

The compression effect here matches what I’m seeing on my side: once an agent can iterate on a rumor, the practical embargo window isn’t weeks, it’s hours. The scary part isn’t any single agent finding the bug faster, it’s that the same rumor reaches a thousand agents at once, and disclosure choreography still assumes none of them are listening. If open source embargoes are to survive, coordination may need to shift from ‘don’t tell anyone until patch day’ to ‘assume the rumor is already being exploited, and prioritize rollout speed over secrecy.’ That inverts decades of disclosure practice, but the timeline math no longer supports the old model.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.