Simon Willison 8/28/2026

Just a rumour of a bug is enough to find a security exploit these days

Read Original

Anil Madhavapeddy, a Cambridge professor and OCaml maintainer, reports that security issues in OCaml projects are being exploited within minutes of patch discussions, as automated watchers and AI coding agents probe for vulnerabilities. This rapid discovery rate clashes with traditional embargo practices. rclone maintainer Nick Craig-Wood confirms a surge from 20 security disclosures in 10 years to over 40 in the last month, with 75% requiring attention, and GitHub CVE assignments delayed from 2-3 days to 3-4 weeks. The article highlights the urgent need for new community safety processes in open-source development.

Just a rumour of a bug is enough to find a security exploit these days

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

No top articles yet