AIs Compress Exploit Timeline

Executive Summary

Schneier reports that AI agents can locate software exploits using only vague rumors, potentially finding them before public patches. The speed of discovery challenges current open‑source embargo practices and suggests a need for new security response processes.


Intelligence Metadata - Source Publisher: Schneier on Security - Published Date: 2026-09-10T10:40:35+00:00 - Category: threat-intel

Original Description: Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source. Simon Wi...

"Don't ruin the present with the ruined past."

— Ellen Gilchrist
Source: Schneier on Security