AIs Compress Exploit Timeline
Schneier argues AI agents can find working exploits from mere rumors of a vulnerability, forcing changes to open source embargo practices.
Bruce Schneier reports that AI agents can locate and develop exploits for vulnerabilities given only a rumor or rough description of the issue, potentially before the public patch ships. He and commenters Simon Willison and Anil argue this discovery speed is incompatible with existing open source embargo practices for coordinated disclosure. The piece calls for redesigned security response processes to keep open source communities safe.