Urgent.News

What's breaking now, across thousands of outlets.

Tech

Just the rumour of a bug is enough to find an exploit these days

A security patch for OCaml's cohttp 6.3.0 was released, addressing a path traversal issue. However, the fix was discovered just minutes after opening the pull request by probes in the webserver logs. The attacker could use their agents to find the exploit by understanding the general nature of the vulnerability. This raises concerns about the need for a change in handling security responses in open source.

The timeline of events has compressed significantly, with exploitation now preceding public patches. The security process should be revised to accommodate this new reality, as just one person searching for the issue class can alert others' agents and enable them to create exploits. Maintainer capabilities have remained flat, and the bottleneck has shifted to defender remediation throughput.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at anil.recoil.org →

More in Tech

More from Friday 28 August →