Analysis · curated 29 Aug 2026

Just a rumour of a bug is enough to find a security exploit these days

Coverage timeline

28 Aug 2026simonwillison.netprimary

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

AI coding agents shrinking the window between bug disclosure and working exploit to minutes breaks existing open-source embargo and disclosure practices, forcing maintainers and defenders to rethink how they coordinate fixes.

A blog post by Anil Madhavapeddy, relayed by Simon Willison, reports that OCaml project security patches shared for discussion draw automated exploit probes within about ten minutes, and that modern coding agents can now locate flaws from the slightest hint of a bug. Anil demonstrated this with his own agents (switching to DeepSeek V4 Pro when Claude Fable refused), and rclone maintainer Nick Craig-Wood confirms his project jumped from ~20 security disclosures in ten years to over 40 in one month.