← 深度专栏/原创观点
原创观点

The Ten-Minute Window: AI and the End of Cyber Embargoes

For decades, the unwritten rule of software security was the "embargo"—a gentleman’s agreement where security researchers and developers quietly fix a...

潜
作者
潜龙编辑部
关注 AI 与社会议题
发布于
2026/10/5
READ
长读
The Ten-Minute Window: AI and the End of Cyber Embargoes
illustration · QianLong editorial

For decades, the unwritten rule of software security was the "embargo"—a gentleman’s agreement where security researchers and developers quietly fix a vulnerability over a few weeks before announcing it to the world. It relied on a simple premise: human attackers need time to figure out how to exploit a flaw. Today, artificial intelligence has crushed that timeline down to mere minutes.

We are entering an era where the slightest rumor or hint of a bug is enough for automated AI agents to track it down and weaponize it. Anil Madhavapeddy, a computer science professor at Cambridge and core maintainer of the OCaml compiler, recently witnessed this firsthand. After sharing a patch for discussion on a public repository, it took only about ten minutes for automated probes to start targeting his website. Bots were already testing the exact vulnerability they were trying to fix.

To understand how this was possible, Madhavapeddy tested the capabilities of modern AI coding agents himself. He discovered that while some AI models with strict safety guardrails, like Claude Fable, would refuse the task of hunting for exploits, others, such as DeepSeek V4 Pro, could effortlessly find the flaws based on minimal information. The AI doesn't need a full blueprint; a breadcrumb is enough.

This hyper-efficiency is completely overwhelming the traditional infrastructure of open-source software. Nick Craig-Wood, the maintainer of the popular open-source tool rclone, shared a stark contrast: in the project’s first ten years, they received about 20 security disclosures. Recently, they received over 40 in a single month.

These aren't just automated false alarms, either. According to Craig-Wood, about 75% of these AI-generated reports contain genuine issues that require developer attention. While finding bugs is objectively a good thing, the sheer volume is drowning maintainers. Even major platforms are feeling the strain; GitHub’s process for assigning CVEs (Common Vulnerabilities and Exposures), which used to take two to three days, now faces backlogs stretching to three or four weeks.

The implications for the digital world are profound. If a vulnerability can be identified and exploited by an AI agent faster than a human can write a patch, the old defensive playbooks are obsolete. Obscurity and time delays are no longer viable shields.

The rise of AI in cybersecurity is a double-edged sword. It is undeniably making our software more secure by surfacing deep-seated flaws, but it is doing so at a pace that our current human-driven institutions cannot handle. The challenge moving forward isn't just about building better AI guardrails—it’s about redesigning how the global developer community collaborates, patches, and protects the digital infrastructure we all rely on.

Key Points

  • AI agents can now locate and exploit software vulnerabilities based on minor hints in a matter of minutes.
  • Open-source maintainers are seeing automated exploit probes almost immediately after discussing patches publicly.
  • The volume of valid, AI-assisted bug reports has surged, overwhelming maintainers and delaying GitHub's CVE assignments by weeks.
  • The traditional practice of keeping bugs secret while fixing them is becoming obsolete due to the speed of AI discovery.

Why It Matters

The unprecedented speed at which AI can identify vulnerabilities means the cybersecurity industry can no longer rely on time buffers, forcing a complete rethink of how we secure digital infrastructure.


Sources:

潛
本文完
潜龙编辑部 · 2026/10/5
潜龙 QianLong · 中文 AI 内容与工具平台