AI news story

AI turns patches into working exploits in 30 minutes, and the 90-day disclosure window is the casualty

Language models find security flaws faster and turn patches into working exploits in minutes. A veteran researcher says the established disclosure process needs to change. The article AI turns patches into working exploits in 30 minutes, and the 90-d

  • AI
  • Source: The Decoder
  • Published: 2026-05-11
  • Signal score: 5
  • 3 sources

Editor's take

AI models are now capable of identifying vulnerabilities in software and generating functional exploits from existing patches in under an hour, significantly compressing the timeline for security researchers. This rapid acceleration threatens the traditional 90-day vulnerability disclosure window, a cornerstone of cybersecurity for decades. The reduced timeframe leaves less time for vendors like Microsoft or Apple to remediate flaws before they can be weaponized by malicious actors, potentially increasing the attack surface for millions of users.

The implications are far-reaching, affecting software developers, cybersecurity firms, and end-users alike. Established security practices, including bug bounty programs and responsible disclosure policies, may require substantial re-evaluation. The speed at which these AI-powered tools can operate suggests a potential arms race where defenders struggle to keep pace with increasingly sophisticated offensive capabilities.

Future developments to monitor include the emergence of specialized AI for exploit generation and the industry's response to this accelerated threat landscape. Specifically, it will be crucial to observe whether vendors adopt faster patching cycles or if new disclosure frameworks, perhaps involving real-time reporting or automated remediation, gain traction. The efficacy of current AI detection tools against these new exploit generation methods will also be a key indicator.

Signal score: 5

This event was corroborated by 3 independent sources. The signal score weighs cross-source corroboration, recency, source weight and topic salience. How we rank stories.

More AI stories

  1. Meet Shepherd: An Open-Source Python Substrate That Lets Meta-Agents Fork, Replay, and Revert Any Agent Run

    MarkTechPost · 2026-08-08

    Long agent runs accumulate state that no transcript records — edited files, a live dev server, installed packages, a warm prompt cache.

  2. Denmark Requires Oral Defenses for Students' Written Work to Counter AI Cheating

    Hacker News · 2026-08-08

    Denmark's Ministry of Education has mandated oral defenses for student assignments to mitigate AI-generated content.

  3. Cloudflare launches Kitesurf, a browser built for AI agents

    TechCrunch · 2026-08-07

    Kitesurf is a cloud-hosted browser designed for AI agents instead of people. It uses less computing power than Chromium for common automation tasks

  4. Pokee AI Releases Pokee-Isaac 28B: A 10M-Token Context Agentic Model Built to Run Inside the Customer Boundary

    MarkTechPost · 2026-08-08

    Pokee AI released Pokee-Isaac 28B, a 28B text-only foundation model with a 10M-token context window built to run inside the customer boundary.

  5. Gentoo bugzilla closed due AI bot scraper overload

    Hacker News · 2026-08-08

    The Gentoo Bugzilla instance has been taken offline due to an overwhelming volume of automated traffic from an AI model scraper.

  6. Before Q, K, and V: Reconstructing the Transformer

    Towards Data Science · 2026-08-08

    Many Transformer explainers start with the finished architecture. We ask why it looks the way it does.