:
[SECURITY]■ STORY TIMELINE

90-DAY VULNERABILITY WINDOW OBSOLETE AS LLMS SPEED EXPLOITS

Large language models are collapsing the timeline between bug discovery and working exploits, making traditional 90-day disclosure policies ineffective. Security researcher Himanshu Anand argues critical vulnerabilities now require immediate patching.

7 SOURCESFIRST SEEN MAY 11, 06:39 AM► READ THE ARTICLE
Hacker News+0m

Article URL: https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/ Comments URL: https://news.ycombi…

Techmeme+1h 57m

Himanshu Anand: The 90-day vulnerability disclosure policy is dead, as LLMs compress bug finding and exploit development…

The Decoder+7h 14m

Language models find security flaws faster and turn patches into working exploits in minutes. A veteran researcher says…

The Guardian — Technology+8h 4m

Criminal groups and state-linked actors appear to be using commercial models to refine and scale up attacks Business li…

The Verge+9h 31m

For the first time, Google says it has spotted and stopped a zero-day exploit developed with AI. According to a report f…

Techmeme+9h 31m

Daniel Stenberg / daniel.haxx.se: curl founder Daniel Stenberg says Mythos identified five vulnerabilities in curl, but…

Engadget+11h 32m

The Google Threat Intelligence Group said its proactive measures stopped a "mass exploitation event."