The Hallway Track
Engineering Insights

Just a rumour of a bug is enough to find a security exploit these days

Simon Willison · Aug 28, 2026 · Engineering Insights

AI coding agents now find security exploits within minutes of patch rumors surfacing publicly

“In the first 10 years of the rclone project we received about 20 security disclosures through GitHub. We had to deal with over 40 in the last month!”

AI coding agents have become so effective at vulnerability discovery that merely hinting at a bug in a public repo triggers automated exploit probes within minutes, breaking traditional open-source embargo practices. Projects like rclone are seeing a 2x+ surge in security disclosures in a single month compared to a decade of prior history. This signals an urgent need to rethink coordinated disclosure workflows as the window between hint and exploit collapses toward zero.

ai-security coding-agents open-source vulnerability-disclosure automated-exploits

Watch / read the original source →