Hi,

> On 29. Apr 2026, at 05:18, Jacob Bachmeyer <[email protected]> wrote:
> 
>> I'm sorely tempted, both due to the increased volume and the risk of 
>> premature disclosure, to just assume that any vulnerability reported as a 
>> result of research using an LLM is trivially discoverable by others, and 
>> give up trying to pretend there's any point to working it under embargo.
> 
> You are correct here:  you should assume that any LLM will give a similar 
> result to another person who asks a similar question.  In other words, 
> LLM-discovered vulnerabilities should be considered already publicly known.

As a further data point backing up this theory: We’re seeing duplicate reports 
of the same issue found by multiple independent groups that use LLMs, within 
the embargo period.

-- 
Clemens Lang
RHEL Crypto Team
Red Hat

Reply via email to