Back to Daily Feed 
AI Agents Find Exploits from Bug Rumors in Minutes, Shaking Open Source Security
Editor's Pick
Originally published on Simon Willison's Weblog by Simon Willison
View Original Article
Share this article:
Summary & Key Takeaways
- AI coding agents are reportedly finding security exploits within minutes of patches being shared publicly.
- This rapid discovery rate is incompatible with traditional open-source embargo practices for new issues.
- Professor Anil Madhavapeddy demonstrated this using his own agents, even after Claude Fable refused the task.
- The rclone project has seen a massive increase in security disclosures, from 20 in 10 years to over 40 in one month.
- GitHub's CVE assignment process is now backlogged, taking weeks instead of days.
- The effectiveness of AI in finding flaws necessitates new processes for community safety.
Our Commentary
This is genuinely unsettling. The idea that a "rumour of a bug" is enough for an AI to weaponize it in minutes? That's a paradigm shift for open-source security. We've always relied on a bit of a grace period, but that's gone now. I don't know how we adapt to this without fundamentally changing how we disclose and patch vulnerabilities. It feels like a race against the machines, and we're already behind.
View Original Article
Share this article: