Security issues in open-source projects are now being actively exploited within minutes of patches being discussed publicly, driven by AI coding agents that can find vulnerabilities from minimal hints. This rapid exploitation rate makes traditional open-source embargo practices obsolete, as automated watchers scan repos and exploit discoveries like rclone have surged from ~20 disclosures per decade to over 40 in a single month.
Background
Open-source security embargo practices traditionally allow vendors days to weeks to prepare patches before public disclosure. AI coding agents are now compressing this timeline to minutes, fundamentally disrupting responsible disclosure norms.
- Source
- Simon Willison
- Published
- Aug 29, 2026 at 06:12 AM
- Score
- 7.0 / 10