ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

AIs Compress Exploit Timeline

infoAI safety & securityimportance 48
AI summary · glm-5.3-flash

Schneier argues AI agents can find working exploits from mere rumors of a vulnerability, forcing changes to open source embargo practices.

Bruce Schneier reports that AI agents can locate and develop exploits for vulnerabilities given only a rumor or rough description of the issue, potentially before the public patch ships. He and commenters Simon Willison and Anil argue this discovery speed is incompatible with existing open source embargo practices for coordinated disclosure. The piece calls for redesigned security response processes to keep open source communities safe.

  • AI agents can derive working exploits from only rumors of a vulnerability
  • Exploitation may now precede public patch availability for open source projects
  • Authors argue coordinated embargo and disclosure practices need redesign for AI-speed discovery
  • Agents need only approximate knowledge of an issue to reproduce it
OrganizationsAnthropicOpenAI
Full article160 words · extracted from schneier.com · click to collapse

Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.

What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.

Simon Willison comments:

Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe.

Tags: AI, exploits, open source

Posted on September 10, 2026 at 6:40 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2026/09/ais-compress-exploit-timeline.html