Frontier models are flooding CVE queues — 90-day disclosure windows must shrink to 30
chrisrohlf · x · 2026-09-23
Security researcher chrisrohlf argues frontier models have lowered the bar for discovering and exploiting vulnerabilities, driving up CVE counts and workload for SWE and vuln-management teams. Yet coordinated disclosure norms still sit at 90 days — workable a decade ago, untenable now; he says we should move to 30 days. That requires trusting the same models to accurately patch and coordinate releases, with the main blockers being confidence in models and reluctance to remove humans from the loop. Warning that the odds of another shellshock, log4j, or heartbleed rise daily, he urges reform before a crisis: shorter timelines and automation in vulnerability management.
More from AGI Musings
- Restaurant manager on AI booking calls: the fake conversationality feels condescending — annetgriffin · 2026-09-23
- Will AI kill folders? Predicting a 'one bucket' era where search does the organizing — NickPassig · 2026-09-23
- Al Gore: all AI data centers emit less than the world's uncovered landfills — jeffclune · 2026-09-23
- Uncle Bob: AI changes nothing—complexity, not tooling, still makes software slow — blaizedsouza · 2026-09-23
- Lean's type theory proves Con(ZF) from excluded middle alone — result found with AI — MikePFrank · 2026-09-23
- VC slams "Made with AI" labels: why not "Made with Camera"? — StewartalsopIII · 2026-09-23