Just a rumour of a bug is enough to find a security exploit these days
2026-08-29 06:12Cybersecurity🔥 28.9 heat score
1sources
1days unfolding
28.9heat score
8mentions
SummaryAI generated
Anil Madhavapeddy, a professor of computer science at Cambridge and the core maintainer of the OCaml compiler, reported that the security vulnerability in the OCaml project was detected by automated attacks just ten minutes after the patch was shared, far exceeding the traditional repair cycle of several days to weeks. Modern coding agents, such as DeepSeek V4 Pro, can quickly identify defects with very little information; existing open-source confidentiality mechanisms can no longer keep up with this speed. Nick Craig-Wood, the maintainer of rclone, confirmed the issue: over the past decade, there were approximately 20 security disclosures, and in the past month, there were more than 40, of which about 75% required handling. The time required for GitHub to assign CVE numbers has increased from 2-3 days to 3-4 weeks, forcing them to release patch versions marked with “CVE-PENDING”.