📊 Full opportunity report: The 90-Day Window Closed. Nobody Sent a Notice. on ThorstenMeyerAI.com — validation score, market gap, and execution plan.
TL;DR
The 90-day window for responsible disclosure has ended without any notice from vendors. AI-driven tools can now exploit vulnerabilities immediately after patches are released, shifting the advantage to attackers.
Security researchers and industry experts confirm that the traditional 90-day window for responsible vulnerability disclosure has effectively ended, with no notices sent by vendors following recent patches. This shift grants attackers immediate access to exploits, significantly reducing the window defenders previously relied on to deploy patches before weaponization.
On April 1, 2026, the Linux kernel team committed a patch addressing the Copy Fail vulnerability. By April 29, 2026, the patch was publicly available, and AI tools capable of analyzing commits and diffing patches can now reconstruct exploits within minutes, not days. This rapid analysis enables attackers monitoring kernel commits to weaponize vulnerabilities before downstream distributions have fully deployed patches.
Industry sources, including security researchers, state that the knowledge floor for discovering vulnerabilities has collapsed. AI systems, such as those used by Theori and Anthropic, can surface zero-day exploits without extensive reverse engineering expertise, fundamentally changing the attacker-defender dynamic. Recent breaches at Vercel and Canvas/Instructure have demonstrated that modern vulnerabilities are less about memory safety bugs and more about trust boundary failures, which are harder to defend against due to their complexity and the lack of mature tooling.
The 90-day window closed.
Nobody sent a notice.
The commit-monitoring window. The knowledge floor. And what Vercel and Canvas reveal about where the bugs actually live.
Copy Fail’s mainline patch landed April 1. Public disclosure was April 29. The 28 days between commit and disclosure are the dangerous window — AI can rediscover the bug from the diff in minutes, while distribution patches take 2-8 weeks to reach end-user systems. Three asymmetries compound: time, expertise, knowledge category. Defender disadvantage compounds across all three.
The patch is now the disclosure event.
Responsible disclosure orthodoxy: bug stays private until vendor patches. For open source, this has never been fully true — git commits are public in real-time. Copy Fail’s mainline patch landed April 1. Public disclosure was April 29. The 28 days between are the dangerous window.
fafe0fa2995a reverting the 2017 in-place AEAD optimization. Patch is now public.INSTANT
TREES
PUBLIC
AVAILABLE
SLOWLY
hardware vulnerability scanner
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
“Please find a security vulnerability.”
No training required.
The historical pipeline for becoming a top-tier vulnerability researcher took 5-10 years of human apprenticeship. Kernel internals. Processor architecture. Exploit-mitigation-bypass craft. Decompiler-output reading. All baked into frontier model training data.
- CS degree with security specialization
- 3-5 years red team / CTF / firm experience
- 2-3 years senior research with reportable findings
- Tacit knowledge: kernel internals, decompiler output reading, exploit-mitigation-bypass craft
- Global pool: ~200-500 senior researchers per decade
- Apprenticeship: mentored by existing experts
- Frontier model API access ($20-200/month for individuals)
- One prompt: “Please find a security vulnerability”
- No security training required (Anthropic / AISI / CETaS verified)
- Tacit knowledge baked in from model training
- Pool of capable actors: millions globally
- Bottleneck: willingness to use it, not skill
The prompt Anthropic used to discover vulnerabilities with Mythos “essentially amounted to ‘Please find a security vulnerability in this program.'” Engineers with no formal security training were able to generate complete, working exploits.

Cute-Patch It Works on My Machine Meme Embroidered Iron on sew on Patch Funny Emblem Programmer Humor
Size: 3 inches tall
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Memory safety isn’t where the breaches happen anymore.
Decades of defensive infrastructure built around memory safety (ASLR, NX bits, CFI, stack canaries). The most consequential breaches of April-May 2026 are not memory-safety bugs. They are trust-boundary failures at integration seams.
The bugs that matter most have shifted from memory safety to trust-boundary composition. OAuth scopes. SaaS-to-SaaS authentication. Multi-tier account models. Third-party app permissions. Environment variable handling. Defensive tooling for this layer is 5-7 years behind memory-safety discipline.
Defensive infrastructure for memory safety is 25+ years mature. Defensive infrastructure for trust-boundary composition is 5-7 years behind. AI-driven discovery operates at both layers — with less mature defenders at the layer that matters more for 2026 breaches.

Cybersecurity Guard: Unlocking the Secrets to Detect, Prevent, and Shield Your Devices from Cyber Threats and Scams
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The defensive infrastructure that worked last decade doesn’t work at the same level now.
Adaptation is necessary. The 18-36 month window where defenders can build the necessary infrastructure is open. Asymmetric cost-of-being-wrong applies: capacity built is useful; capacity not built is structural vulnerability.
+ SECURITY TEAMS
PUBLISHERS
POLICYMAKERS
EVERYONE ELSE
The 90-day window collapsed. The knowledge floor collapsed. The bugs moved layers. Three asymmetries compound. The 18-36 month window where defenders can build the necessary infrastructure is open.

The Practice of Network Security Monitoring: Understanding Incident Detection and Response
Used Book in Good Condition
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Implications of the Disappearance of the 90-Day Window
This development fundamentally alters the cybersecurity landscape, shifting the advantage from defenders to attackers. The ability for AI systems to analyze patches immediately upon release means vulnerabilities are exploited almost as soon as they are publicly disclosed or even privately known. This accelerates the threat timeline, making traditional patching and defense strategies less effective. Organizations must now consider real-time monitoring and AI-driven defenses to mitigate risks, as the old paradigm of waiting 90 days for patch deployment no longer holds.
Collapse of the Responsible Disclosure Framework
The 90-day window was established in the early 2000s as a compromise between researchers and vendors, allowing time for patches before vulnerabilities became public knowledge. This period depended on assumptions about reverse engineering difficulty, patch analysis time, and patch deployment speed. However, with AI now capable of analyzing code commits and generating exploits within minutes, these assumptions no longer apply. The recent disclosures of breaches at Vercel and Canvas highlight the shift towards trust boundary vulnerabilities, which are less amenable to traditional defenses and require new security paradigms.
“Our recent breach underscores the importance of rethinking security at the trust boundary, beyond memory safety issues.”
— Vercel security spokesperson
Unclear Impact on Future Patch and Disclosure Practices
It remains unclear how vendors and security communities will adapt to this new paradigm. While some suggest moving toward real-time disclosure and automated patching, the effectiveness and adoption of such measures are still uncertain. Additionally, the extent to which attackers will leverage AI for widespread exploitation in the coming months is not yet fully known.
Next Steps for Security Stakeholders
Security organizations and vendors are expected to accelerate the adoption of AI-driven monitoring tools and real-time threat detection. Researchers may also shift toward more immediate disclosure practices or develop new standards to address the rapid exploit development cycle. Monitoring the evolution of breach techniques at companies like Vercel and Canvas will be critical to understanding and mitigating emerging risks.
Key Questions
Why is the 90-day disclosure window no longer effective?
Because AI tools can analyze patches and generate exploits within minutes, eliminating the time advantage that the window provided to defenders.
What types of vulnerabilities are now most exploited?
Trust boundary failures at integration points, such as OAuth scopes and SaaS-to-SaaS permissions, are now the most exploited vulnerabilities.
How are organizations expected to respond?
Organizations will need to implement real-time monitoring, AI-based threat detection, and adopt faster patching workflows to keep pace with rapid exploit development.
What are the risks of AI-powered exploits?
They can be developed and deployed much faster than traditional exploits, increasing the likelihood of widespread, rapid breaches.
Source: ThorstenMeyerAI.com