Voices
Simon Willison: 'Just a rumour of a bug is enough to find a security exploit these days'
Willison's August 28 post collects two maintainer accounts of AI coding agents weaponizing patch discussions. Cambridge's Anil Madhavapeddy reports automated watchers probing traversal sequences within 10 minutes of a patch being shared, and rclone's Nick Craig-Wood says the project took ~20 security disclosures in its first decade but more than 40 in the last month alone, with a 75% hit rate and CVE assignment slipping from 2-3 days to 3-4 weeks. The concrete consequence for anyone maintaining open source is that coordinated disclosure windows measured in days no longer exist.
↳ Follow the thread