[object Object]
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.
What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.
Simon Willison comments:
Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe.
Tags: AI, exploits, open source
Posted on September 10, 2026 at 6:40 AM • 4 Comments
Sidebar photo of Bruce Schneier by Joe MacInnis.
Reproduced in full under licence from Schneier on Security. © Schneier on Security. Written by Bruce Schneier.
Coverage
One outlet has carried this so far.
2026-09-10 10:40 UTC
Related stories
- Windows 11 KB5124008 update breaks domain trust for some users
BleepingComputer · 2026-09-16
- CISA decides weekly vulnerability bulletin isn't necessary anymore
The Register · 2026-09-16
- Malware bypasses browser checks to force install Chrome, Edge extensions
BleepingComputer · 2026-09-16
- Google Pixel phones pwned in zero-click attacks
The Register · 2026-09-16
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16