Skip to content

Topic

AI-Assisted Exploitation

Attacker use of AI-generated exploit scripts against critical infrastructure targets.

Current stories

buildOne report1 publisher

Probes hit a maintainer's webserver ten minutes after his fix PR went public

Anil Madhavapeddy's account of the cohttp 6.3.0 path traversal fix puts a number on the gap between publishing a patch and being probed for the bug it closes. The three alternatives he examined each cost a small maintainer something.

Publishers:tldrsec.com

Reality

Evidence42
Adoption18
Hype gap+32
Incentives40
Confidence45
buildOne report1 publisher

Opening the cohttp fix PR drew traversal probes within ten minutes

Anil Madhavapeddy patched a path traversal bug in OCaml's cohttp and found probes for it in his logs ten minutes after opening the fix PR. His own agent had already built the exploit from a bug-class hint.

Publishers:anil.recoil.org

Reality

Evidence52
Adoption44
Hype gap+14
Incentives55
Confidence57
securityConfirmed3 publishers

Public exploit code for CVE-2026-62911 is outpacing patching on 21,899 exposed Exchange servers

Microsoft patched the Exchange authentication bypass on August 11. Shadowserver's September 1 scan still counts 21,899 internet-facing servers unpatched, and NCSC-NL says working exploit code for full mailbox takeover is circulating.

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 68%
Investor
Investor 12%

Reality

Evidence72
Adoption30
Hype gap+18
Incentives70
Confidence68