AI Briefing
KO

The 90-Day Disclosure Policy Is Dead

·2026.05.11 17:02

Key point

As LLMs accelerate vulnerability discovery and exploit development, the traditional 90-day responsible disclosure model is becoming ineffective.

Details

As LLMs dramatically speed up vulnerability discovery and exploit development, the 90-day Responsible Disclosure model that has long been the security industry standard is losing its effectiveness.

The Security Paradigm Shift Caused by LLMs

  • Simultaneous rediscovery phenomenon: As LLM-assisted researchers use similar tools and prompts, duplicate reports for the same vulnerability are observed piling up within a short period. In fact, one payment validation bug was reported by 11 people over 6 weeks.
  • Accelerated exploit development: In the past, creating an exploit after patch analysis took several days, but now working code can be produced with AI in just 30 minutes. The React DoS patch case is a representative example.
  • Automated kernel vulnerability scanning: There have also been cases where AI was used to automatically scan a specific Linux kernel subsystem for about 1 hour, uncovering the Copy Fail vulnerability that had been left unaddressed for 9 years.

Conclusion and Response Direction

The 90-day disclosure grace period has now been transformed into a structure that gives attackers a head start rather than protecting users. Companies need to actively adopt LLMs in their security pipelines and establish an agile response system that classifies critical issues as P0 for immediate handling.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.