漏洞传闻即可引发安全利用,开源安全流程面临挑战
原标题:Just a rumour of a bug is enough to find a security exploit these days
AI 摘要
剑桥大学计算机科学教授兼OCaml编译器核心维护者Anil Madhavapeddy报告称,OCaml项目在补丁讨论后几分钟内就遭到利用尝试,表明自动化监控者正关注公共仓库。现代编码代理能快速发现漏洞,仅凭漏洞传闻即可找到利用方法,这使现有开源安全披露流程面临挑战。rclone维护者Nick Craig-Wood也证实,该项目最近一个月收到超过40份安全披露,而GitHub分配CVE的时间从2-3天延长至3-4周。
正文节选
28th August 2026 - Link Blog Just a rumour of a bug is enough to find a security exploit these days (via) Anil Madhavapeddy is a professor of computer science at Cambridge and a core maintainer of the OCaml compiler. In this somewhat alarming post he reports that security issues in OCaml projects are seeing evidence of attempted exploits within minutes of patches being shared for discussion: This normally takes a few days and a release within a week or two is reasonable. Within about ten minutes