Agents turn a bug-fix PR into exploit probes in ~10 minutes

The rumour is now the exploit — maintainers are dropping embargoes and shipping CVE-PENDING as agents outrun disclosure. Plus: cheap 30-second video via API.

Nowline AUG 30 10:00 PM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • Ten minutes from public PR to live probes

    An OCaml cohttp maintainer opened a public pull request fixing a percent-encoded path-traversal bug; within roughly 10 minutes his server was fielding probes for exactly that traversal pattern. Agents now need only a vague hint of a flaw to reconstruct the exploit, so the days-to-weeks embargo window builders relied on is effectively gone.

  • Disclosures doubled, CVEs now take weeks

    rclone's maintainer reports going from ~20 security disclosures in a decade to 40+ in a single month, while CVE assignment slipped from 2-3 days to 3-4 weeks — pushing teams to ship releases stamped 'CVE-PENDING.' If you maintain anything widely used, expect the triage load and the paperwork to climb.

  • What to change before your next security fix

    The maintainer playbook is shifting: develop patches on genuinely private infrastructure instead of a public branch, drop embargoes in favor of Chrome-style continuous releases, and stand up protocol-layer 'virtual patches' (a WAF rule for the bad pattern) the moment a fix enters review — defenses that ship before the code does.

  • Elsewhere: Wan 3.0 Prime video hits OpenRouter

    Alibaba's Wan 3.0 Prime — a fast-mode variant that does 30-second single-shot text- and image-to-video — is now callable through OpenRouter from about $0.068 per second of output, so you can wire generated clips into an app with one API key.