Agents turn a bug-fix PR into exploit probes in ~10 minutes
The rumour is now the exploit — maintainers are dropping embargoes and shipping CVE-PENDING as agents outrun disclosure. Plus: cheap 30-second video via API.

Copy markdown
Ten minutes from public PR to live probes
An OCaml cohttp maintainer opened a public pull request fixing a percent-encoded path-traversal bug; within roughly 10 minutes his server was fielding probes for exactly that traversal pattern. Agents now need only a vague hint of a flaw to reconstruct the exploit, so the days-to-weeks embargo window builders relied on is effectively gone.
Disclosures doubled, CVEs now take weeks
rclone's maintainer reports going from ~20 security disclosures in a decade to 40+ in a single month, while CVE assignment slipped from 2-3 days to 3-4 weeks — pushing teams to ship releases stamped 'CVE-PENDING.' If you maintain anything widely used, expect the triage load and the paperwork to climb.
What to change before your next security fix
The maintainer playbook is shifting: develop patches on genuinely private infrastructure instead of a public branch, drop embargoes in favor of Chrome-style continuous releases, and stand up protocol-layer 'virtual patches' (a WAF rule for the bad pattern) the moment a fix enters review — defenses that ship before the code does.
Elsewhere: Wan 3.0 Prime video hits OpenRouter
Alibaba's Wan 3.0 Prime — a fast-mode variant that does 30-second single-shot text- and image-to-video — is now callable through OpenRouter from about $0.068 per second of output, so you can wire generated clips into an app with one API key.