Researcher reports immediate vulnerability flood from LLM audits
2Sep 19 6:19 PM · 4d ago · 2 comments · 1 source · development 2 of 5
Datasette maintainer Simon Willison, citing a recent security audit of his project using GPT-6 Astra and Claude Fable 5.1, reports spending a full week patching extremely obscure vulnerabilities that LLMs discovered—vulnerabilities that had gone unspotted by humans for extended periods. He contradicts the one-year timeline, stating "We don't even have a year."
“I ran a security audit using GPT-6 Astra and Claude Fable 5.1 against my main open source project (Datasette) recently and then spent a full *week* fixing vulnerabilities that they found, many of which were extremely obscure, hence why nobody had spotted them before.”
We don't even have a year. I ran a security audit using GPT-6 Astra and Claude Fable 5.1 against my main open source project (Datasette) recently and then spent a full *week* fixing vulnerabilities that they found, many of which were extremely obscure, hence why nobody had spotted them before. An obscure vulnerability is still a vulnerability…
I’m in the middle of reading a book on the stuxnet attack and one thing that really stood out to me is that at least two of the zero days had been publicly published or disclosed for a year or more.