AI agents are disrupting open source security disclosure
Cambridge professor and OCaml maintainer Anil Madhavapeddy says AI agents turn public clues about vulnerabilities into working exploits within minutes, undermining traditional disclosure embargoes. A GPT-4 agent exploited 87% of vulnerabilities in a benchmark when given CVE descriptions, versus 7% without them.
- GPT-4 agent exploited 87% of benchmark vulnerabilities with CVE descriptions, 7% without
- Madhavapeddy saw probes matching the bug pattern minutes after opening a fix PR
- rclone received over 40 vulnerability reports in a month versus 20 in its first 10 years
- QEMU shortened vulnerability embargoes due to automated discovery
Read next
Security