Just a rumour of a bug is enough to find a security exploit these days
Just a rumour of a bug is enough to find a security exploit these days Anil Madhavapeddy is a professor of computer science at Cambridge and a core maintainer of the OCaml compiler. In this somewhat alarming post he reports that security issues in OCaml projects are seeing evidence of attempted exploits within minutes of patches being shared for discussion: This normally takes a few days and a…
A professor of computer science at Cambridge has reported that security issues in OCaml projects are being exploited within minutes of patches being shared. Anil Madhavapeddy, the maintainer of the OCaml compiler, noticed automated probes for traversal sequences in public repositories within just ten minutes of a patch being available.
This rapid discovery rate is incompatible with existing open source practices for disclosing new issues. Security disclosure for rclone project has increased dramatically in the last month, with almost 50 security disclosures compared to about 20 over the past ten years. This rapid pace of discovery has caused significant strain on maintainers, with some projects requiring AI tools to triage and provide fixes.
GitHub is now taking longer to assign CVEs, with assignments taking up to four weeks instead of the previous two to three days.
Written by urgent.news from Simon Willison's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.