WorkThe story, in brief

AI turns patches into working exploits in 30 minutes, and the 90-day disclosure window is the casualty

90 days isn't enough anymore. AI can turn security patches into working exploits in 30 minutes—and the industry's disclosure window is already broken.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

AI's ability to rapidly weaponize patches creates a critical governance gap: the traditional 90-day vendor disclosure window, designed for human researchers, is now obsolete. This forces a reckoning on coordinated disclosure policy and enterprise security strategy.

The key facts

4 to know
  1. LLMs can generate working exploits from patches in 30 minutes

  2. Traditional 90-day disclosure window no longer adequate for AI-accelerated threat landscape

  3. Veteran security researcher calling for policy change

  4. Established disclosure process under threat

Go to the source

The Decoderthe-decoder.com

Publisher excerpt: Language models find security flaws faster and turn patches into working exploits in minutes. A veteran researcher says the established disclosure process needs to change.
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work