Switch language한국어
Back to the list

Standard 90-day vulnerability disclosure policy is likely dead thanks to AI, expert warns that AI can weaponize patches in 30 minutes — LLM-assisted bug-hunting ushers in a new cyberworld order

TL;DR AI

Key summary

2 min read
  1. AI-assisted code analysis is shrinking the gap between bug discovery, public disclosure, and real-world exploitation.

  2. A researcher cited Linux kernel flaws and a React exploit reproduced in about 30 minutes to show how quickly duplicates and proof-of-concepts now appear.

  3. The warning is that standard disclosure and patch windows, including the 90-day norm, may no longer be enough for critical bugs.

  4. Security teams may need to treat serious findings as immediate priorities and tighten triage, patching, and defensive workflows.

Read the original