Just a rumour of a bug is enough to find a security exploit these days
ai
Simon Willison's Weblog reports that security researchers are seeing exploits within minutes of a bug being hinted at, thanks to AI coding agents. A Cambridge professor and OCaml maintainer found his site probed for attacks just ten minutes after sharing a patch for discussion. The rclone project has seen security disclosures jump from about twenty in ten years to over forty in the last month, with most containing something worth investigating. The rapid pace is straining traditional embargo practices, and maintainers are calling for new processes to keep open source communities safe.
Source: https://simonwillison.net/2026/Aug/28/just-a-rumour-of-a-bug/
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton