The traditional 90-day vulnerability disclosure policy is likely dead, according to security experts. AI-assisted bug hunting has accelerated the timeline for exploiting vulnerabilities. Researchers warn that attackers can now weaponize patches in as little as 30 minutes using large language model tools.
Duplicate reports surge with AI tools
Triage engineer @d0rsky observed a wave of duplicate vulnerability reports within days of a new disclosure. Multiple researchers using LLMs converge on the same bugs almost simultaneously. Researcher Himanshu Anand created an exploit for a patched React vulnerability in 30 minutes using an LLM. Anand urges treating every critical security issue as P0 and fixing immediately.

Anand stated that the 30 day window between vulnerability and fix assumes attackers are slower than your release train. He added that if you are reading CVE descriptions while attackers are reading git log –diff-filter=M, you are already behind. The Linux kernel vulnerabilities Copy Fail and Dirty Frag were disclosed before patches were widely available.
@d0rsky questioned that if researchers can replicate findings so quickly, what is stopping black-hats from doing the same before the issue is fixed. The rapid convergence of AI-assisted research suggests that the current disclosure model may no longer be viable. Security teams may need to adopt faster patch cycles and treat every critical issue as an emergency.




Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.