Analysis · curated 29 Aug 2026
Just a rumour of a bug is enough to find a security exploit these days
First reported simonwillison.net
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
AI coding agents shrinking the window between bug disclosure and working exploit to minutes breaks existing open-source embargo and disclosure practices, forcing maintainers and defenders to rethink how they coordinate fixes.
A blog post by Anil Madhavapeddy, relayed by Simon Willison, reports that OCaml project security patches shared for discussion draw automated exploit probes within about ten minutes, and that modern coding agents can now locate flaws from the slightest hint of a bug. Anil demonstrated this with his own agents (switching to DeepSeek V4 Pro when Claude Fable refused), and rclone maintainer Nick Craig-Wood confirms his project jumped from ~20 security disclosures in ten years to over 40 in one month.