The Information Machine
Updated today·following since 24 Aug 2026·Day 4·4 sources

AI tools compressing software exploit timelines

The gist

AI agents compress exploit timelines to hours as attack volumes climb

The acceleration affects multiple attack surfaces simultaneously: automated probing of public repositories now begins within minutes of patch disclosure, disabling traditional embargo windows; state-level adversaries are integrating AI tools to scale attack volume; and CVE assignment infrastructure is already backlogged. Open-source security practices built around days-long response windows no longer match the actual threat timeline.

The full picture

Palo Alto Networks' Unit 42 is investigating an agentic cyberattack that exploited 50 vulnerabilities within a single organization in 10 hours, work that would traditionally take weeks. Chinese state-backed hackers more than doubled their attack volume after integrating DeepSeek into malware development and reconnaissance. Automated agents began probing an OCaml project for vulnerabilities within about ten minutes of a patch being shared for discussion. A METR analysis found that reported vulnerability rates for major projects, including cURL, OpenSSL, Firefox, and Microsoft, dramatically accelerated in 2026 compared with 2025, with the same pattern visible in aggregate databases including the US NVD and OSV. The authors characterize the shift as a 'phase change' in AI capability for cybersecurity in 2026, analogous to what occurred for coding in 2025. rclone maintainer Nick Craig-Wood reported over 40 security disclosures in a single month, against roughly 20 across the project's first ten years combined, with about 75% containing a genuine issue. GitHub CVE assignment times have ballooned from 2-3 days to 3-4 weeks, forcing maintainers to ship releases with 'CVE-PENDING' in changelogs. Russian-speaking hackers allegedly used the Cursor coding tool to breach a Belgian chemical company and at least six other firms. CrowdStrike and Okta both raised earnings forecasts citing increased AI-driven threats.

How it developed
29 August 2026

Palo Alto Networks' Unit 42 is investigating an agentic attack that exploited 50 vulnerabilities within one organization in 10 hours, consistent with a METR analysis published August 29 finding that 2026 vulnerability rates for cURL, OpenSSL, Firefox, and Microsoft dramatically outpaced 2025, a shift the authors frame as a 'phase change' in AI cybersecurity capabilities.

Automated agents probed an OCaml project within ten minutes of a patch being shared, and rclone received over 40 disclosures in a month against 20 across its first decade.

First citedImport AISemafor TechnologySimon Willison
28 August 2026

Automated agents probed OCaml project within 10 minutes of patch discussion; rclone maintainer reports 40+ disclosures in one month vs 20 in ten years; GitHub CVE times balloon from days to weeks

25 August 2026

Report: Chinese state-backed hackers more than doubled attack volume after integrating DeepSeek into malware development and reconnaissance

24 August 2026

METR analysis published finding dramatic 2026 acceleration in vulnerability reporting rates across major projects and aggregate databases

Sources
Semafor Technology
The daily email

Want this in your inbox?

I send a short email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free