AI Agents Accelerate Exploitation: Attacks Within Minutes of Patch Discussion
A Cambridge professor reports exploit attempts mere minutes after patch discussions, while rclone sees a surge in security disclosures, signaling a new era of AI-driven vulnerability hunting.

Anil Madhavapeddy, a computer science professor at the University of Cambridge and core maintainer of the OCaml compiler, recently reported that open-source projects are seeing exploit attempts within minutes of patch discussions. In a blog post, he noted that roughly ten minutes after his site published a security patch discussion, he detected probes targeting percent-encoded traversal sequences, indicating that automated monitoring tools are tracking public repositories in real time. Previously, such attacks typically took days, with patch release cycles spanning one to two weeks.
Madhavapeddy pointed out that modern coding agents can efficiently identify vulnerabilities, locating and exploiting them based on mere hints of a flaw. He himself used his own agent to demonstrate this, switching to DeepSeek V4 Pro to complete a similar operation after Claude refused the task. He argued that the existing embargo process for open-source vulnerability disclosure is struggling to keep pace with such rapid exploitation, and the community needs to explore new security collaboration mechanisms.
Nick Craig-Wood, a maintainer of rclone, confirmed similar trends in Hacker News comments: the project received only about 20 security disclosures in its first decade, but over 40 in the last month alone, with roughly 75% containing valid issues that required attention. GitHub's timeline for assigning CVE numbers has also stretched from 2-3 days in the past to 3-4 weeks now, forcing maintainers to mark point releases with "CVE-PENDING."
Source: https://simonwillison.net/2026/Aug/28/just-a-rumour-of-a-bug/
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-08-28
- Last updated
- 2026-08-29
- Content type
- Newsflash
- Source material
- View original ↗


