Trusence Every claim has a source
Last updated 3 October 2026 Search Türkçe
← All stories
Security

Microsoft says AI is shrinking the window between bug discovery and abuse

Open source maintainers are now seeing probing begin minutes after a fix is posted, adding pressure to disclosures already moving faster than many systems can patch.

Microsoft says attackers are already getting more value from AI than defenders, and it warns that this is compressing the time available to find, patch, and weaponize vulnerabilities. In its 2026 Digital Defense Report, the company says the median gap from in-the-wild discovery to weaponization is now below 24 hours, while remediation remains much slower because many systems cannot ship fixes quickly. The report also says AI is speeding up malware creation, post-compromise work, and social engineering, including use by Chinese, Russian, and North Korean threat actors. Separately, open source maintainers are seeing the same pressure: Anil Madhavapeddy says a fix PR for a path-traversal bug triggered live probing within minutes, and rclone maintainer Nick Craig-Wood says GitHub disclosures jumped from about 20 in 10 years to more than 40 in a month.

Why it matters

For maintainers and defenders, the practical change is that disclosure no longer buys much time. Microsoft says weaponization is now happening in under 24 hours, while remediation still lags, so a fix can be followed almost immediately by active probing and more follow-on work for the people who have to keep software safe. That shifts security work toward faster coordination and shorter reaction windows.

Sources

  • InfoQ
  • BleepingComputer