AuraTracer智迹闻
中文

EVENT DOSSIER

Just a rumour of a bug is enough to find a security exploit these days

2026-08-29 06:12 Cybersecurity 🔥 28.9 heat score
1sources
1days unfolding
28.9heat score
8mentions
SummaryAI generated

Anil Madhavapeddy, a professor of computer science at Cambridge and the core maintainer of the OCaml compiler, reported that the security vulnerability in the OCaml project was detected by automated attacks just ten minutes after the patch was shared, far exceeding the traditional repair cycle of several days to weeks. Modern coding agents, such as DeepSeek V4 Pro, can quickly identify defects with very little information; existing open-source confidentiality mechanisms can no longer keep up with this speed. Nick Craig-Wood, the maintainer of rclone, confirmed the issue: over the past decade, there were approximately 20 security disclosures, and in the past month, there were more than 40, of which about 75% required handling. The time required for GitHub to assign CVE numbers has increased from 2-3 days to 3-4 weeks, forcing them to release patch versions marked with “CVE-PENDING”.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
Anil MadhavapeddyCambridgeClaude FableDeepSeek V4 ProGitHubNick Craig-WoodOCamlrclone

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
Anil Madhavapeddy × Cam…1Anil Madhavapeddy × Cla…1Anil Madhavapeddy × Dee…1Anil Madhavapeddy × Git…1Anil Madhavapeddy × Nic…1Cambridge × Claude Fable1

SignalsSIGNALS

Keyword heat
  • Anil Madhavapeddy1
  • Cambridge1
  • OCaml1
  • DeepSeek V4 Pro1
  • Claude Fable1
  • Nick Craig-Wood1
  • rclone1
  • GitHub1

All reports (1)SOURCES

S Simon Willison en 2026-08-29 06:12

Just a rumour of a bug is enough to find a security exploit these days

剑桥计算机科学教授、OCaml 编译器核心维护者 Anil Madhavapeddy 报告称,OCaml 项目安全漏洞在补丁共享后仅约十分钟即遭自动化攻击探测,远超传统数天至数周的修复周期。现代编码智能体(如 DeepSeek V4 Pro)能利用极少量线索快速定位缺陷,现有开源保密机制已无法应对此速度。rclone 维护者 Nick Craig-Wood 证实该问题:过去十年收到约 20 起安全披露,而最近一个月超过 40 起,其中约 75% 需处理;GitHub 分配 CVE 编号时间从原来的 2-3 天延长至 3-4 周,导致其不得不发布带有"CVE-PENDING"标记的补丁版本。