the 90 day disclosure policy is dead

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

LLMs have fundamentally broken the assumptions behind the 90-day responsible disclosure model. With AI-assisted tools, multiple unrelated researchers now independently find the same critical bugs within weeks, and patch diffs can be reverse-engineered into working exploits in under 30 minutes. Three real-world examples illustrate this: 11 researchers independently reported the same payment bypass bug in 6 weeks; a React security patch was turned into a working exploit in 30 minutes using AI; and two back-to-back Linux kernel privilege escalation vulnerabilities (Copy Fail and Dirty Frag) were weaponized by nation-state actors within days of disclosure, with Dirty Frag's embargo broken within hours. The author argues that 90-day windows, monthly patch cycles, and advisory-based response are all obsolete. The call to action: treat every critical bug as P0, fix immediately, and integrate AI into CI/CD pipelines for real-time security review, patch analysis, and dependency scanning on the defensive side.

15m read timeFrom blog.himanshuanand.com
Post cover image
Table of contents
TLDR ⌗the old world (rest in peace) ⌗story 1: 10 people, 1 bug, 6 weeks ⌗story 2: 30 minutes from patch to exploit ⌗story 3: the week linux caught fire ⌗so what is actually dead here ⌗what the industry needs to do (and I am not sugarcoating this) ⌗final thoughts ⌗
279 Impressions