oss-sec mailing list archives

Re: Coordinated Disclosure in the LLM Age


From: ROI AI <sales () roiai ca>
Date: Wed, 20 May 2026 22:26:21 -0700

People are shooting the messengers here.   The fact is - we are going through a generational security event due to the 
advancement of LLMs.



It is also both trivial and extremely effective to use Agentic analysis to filter security reports.



As for 'duplicates', people are claiming this when I have seen little evidence.  I reported a dozen or so to one major 
project and no one has yet claimed invalid or duplicate.  



Moreover, if 'duplicates' are found, then that is a good signal for prioritization.



Let's stop talking about how the vulns are found and start fixing them with urgency.


ROI AI








From: Alan Coopersmith <alan.coopersmith () oracle com>
To: <oss-security () lists openwall com>
Date: Wed, 20 May 2026 10:52:37 -0700
Subject: Re: [oss-security] Coordinated Disclosure in the LLM Age



On 4/28/26 07:58, Jeremy Stanley wrote: 
I'm sorely tempted, both due to the increased volume and the risk of premature 
disclosure, to just assume that any vulnerability reported as a result of 
research using an LLM is trivially discoverable by others, and give up trying to 
pretend there's any point to working it under embargo. 
 
Other maintainers under similar floods seem to agree: 
 
Linux kernel: 
 - https://lkml.org/lkml/2026/5/17/896  
 - https://docs.kernel.org/process/security-bugs.html  
 
DNS servers (BIND, Unbound, PowerDNS): 
- https://indico.dns-oarc.net/event/56/contributions/1233/  
- https://indico.dns-oarc.net/event/56/contributions/1233/attachments/1180/2539/presentation.pdf  
 
-- 
 -Alan Coopersmith- mailto:alan.coopersmith () oracle com  
 Oracle Solaris Engineering - https://blogs.oracle.com/solaris
Confidential communication. No warranties or commitments unless in a signed agreement. If received in error, notify 
sender and delete. Unauthorized use prohibited.




Current thread: