Tech & AI News
Hacker News

Just the rumour of a bug is enough to find an exploit these days

A security fix for OCaml’s cohttp 6.3.0 was released after the author discovered live server probes using the path-traversal pattern minutes after opening the PR. The author’s own AI agents could generate an exploit in under a minute, showing that public disclosure of a bug’s existence can enable rapid automated exploitation. The incident illustrates that traditional security embargoes are ineffective when attackers can use broad search directions to create exploits before a patch is available.