/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The 90-day vulnerability disclosure policy is dead, as LLMs compress bug finding and exploit development time, and critical issues must be patched immediately

Table of Contents  — story 2: 30 minutes from patch to exploit  — what the industry needs to do (and I am not sugarcoating this)

Himanshu Anand

Context & Ripple Effects

The related coverage traces Project Zero’s long-running use of a 90-day disclosure deadline, with limited grace periods and, later, a post-fix publication cushion intended to give users time to deploy updates.

That model has always depended on vendors’ patch velocity. Comparative reporting in 2022 showed wide variation among major platform maintainers, making a shorter effective remediation window especially consequential for slower responders.

First-order effects

  • The article’s central claim puts pressure on vendors to treat critical flaws as immediate incident-response work rather than issues managed against a standard 90-day disclosure clock.
  • Security teams and customers would have less time between a fix becoming available and likely exploitation, increasing the operational importance of rapid patch distribution and deployment.

Second-order effects

  • Disclosure programs and bug-bounty operators may need to distinguish more sharply between critical, readily weaponized flaws and lower-severity issues, rather than relying on one default deadline.
  • Vendors with slower patch cycles face greater comparative exposure: researchers, enterprise buyers, and downstream operators can increasingly judge them on time-to-fix as well as on the existence of a patch.

Third-order effects

  • If exploit development continues to accelerate, vulnerability handling is likely to shift from calendar-based coordinated disclosure toward risk-based disclosure and continuously exercised emergency patch processes.
  • The result could be a wider split between platforms built for rapid update delivery and ecosystems where fragmented deployment leaves known critical flaws exposed after fixes are released.

The trend: AI-assisted security research is tightening the interval between flaw discovery, patch release, and weaponization, weakening disclosure policies designed around longer remediation cycles.

Discussion

  • r/netsec r on reddit
    The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice.
  • Phoronix Michael Larabel on x
    Linux 7.0.6 Released To Finish Mitigating the Dirty Frag Vulnerability
  • @swtch.com Russ Cox on bluesky
    “Your monthly maintenance window is not a safety margin.  It is an attack window.”  —  blog.himanshuanand.com/2026/05/the- ...
  • @kevinr.free-dissociation.com Kevin Riggle on bluesky
    Another major Linux local root exploit just dropped.  (Embargo was broken so we're still waiting on patches to land in the mainline kernel, let alone with distros)  —  github.com/V4bel/dirtyf...
  • @dinosn Nicolas Krassas on x
    The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice. https://blog.himanshuanand.com/ ...