Fetching from the wire…
Top 5 · 2026-04-04 · source-backed
Two senior Linux kernel maintainers independently confirmed something uncomfortable this week. Willy Tarreau reported that security vulnerability reports jumped from 2-3 per week to roughly 10 per week over the past year. Greg Kroah-Hartman confirmed the trend and added a detail that should worry everyone: months ago, the AI-generated reports were "funny" and obviously wrong. Then something changed about a month ago. The reports are now high-quality and accurate. They're overwhelming maintainer bandwidth.
Separately, security veteran Thomas Ptacek published an essay arguing that frontier coding agents will "drastically alter both the practice and economics of exploit development." His thesis: pointing an agent at a source tree and typing "find me zero days" will produce substantial amounts of high-impact vulnerability research, because LLMs encode enough correlation across vast code bodies that the implicit search problems of vuln research play to their core strengths.
Then there's Hexstrike-AI, disclosed by Check Point Research. An offensive framework that lets AI models autonomously run 150+ cybersecurity tools for penetration testing and vulnerability discovery. Threat actors claim it reduces exploitation time from days to under 10 minutes. From finding to weaponization in the time it takes to make coffee.
And the UK NCSC published data showing Claude Opus 4.6 completed roughly half of a 32-step enterprise network simulation for about £65 per attempt. Best AI models improved offensive capability 6x in 18 months.
Here's the problem nobody's solving: who reviews the AI's homework? Finding vulnerabilities is getting automated. Fixing them still requires human maintainers. The Linux kernel has a handful of people reviewing security patches for the most critical piece of open-source software on the planet, and they're already drowning. This isn't a Linux problem. Any popular open-source project used as context by coding agents will face the same discovery flood. The bottleneck has shifted from finding bugs to triaging fixes, and I don't see a good answer yet.
Each link below shares sources, entities, or timing with this story.
Claude Opus built by Anthropic / Shared entity: Claude Opus / Same source domain / Shared topic / What happened next / Tension
Linked by a graph relationship (Claude Opus built by Anthropic); both cover Claude Opus; reported by the same outlet (simonwillison.net).
Linked by a graph relationship (Claude Opus built by Anthropic); both cover Claude Opus; reported by the same outlet (simonwillison.net).
Claude Code supports Linux / Shared entities / What happened next
Linked by a graph relationship (Claude Code supports Linux); both cover Linux, Separately, Then; picks up the Linux thread on 2026-07-21.
Claude Opus built by Anthropic / Shared entities / Same source domain / What happened next
Linked by a graph relationship (Claude Opus built by Anthropic); both cover Linux, Then; reported by the same outlet (simonwillison.net).
Cursor supports Claude Opus / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Cursor supports Claude Opus); both cover Claude Opus, Then; overlapping topics (agent, model).
GitHub Copilot uses Claude Opus / Shared entity: LLMs / Shared topic / What happened next / Tension
Linked by a graph relationship (GitHub Copilot uses Claude Opus); both cover LLMs; overlapping topics (agent, coding, model).
Claude Opus built by Anthropic / Shared entity: Linux / Same source domain / Shared topic / What happened next
Linked by a graph relationship (Claude Opus built by Anthropic); both cover Linux; reported by the same outlet (simonwillison.net).
Cursor supports Claude Opus / Shared entity: Claude Opus / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Cursor supports Claude Opus); both cover Claude Opus; reported by the same outlet (simonwillison.net).