Hi, > On 29. Apr 2026, at 05:18, Jacob Bachmeyer <[email protected]> wrote: > >> I'm sorely tempted, both due to the increased volume and the risk of >> premature disclosure, to just assume that any vulnerability reported as a >> result of research using an LLM is trivially discoverable by others, and >> give up trying to pretend there's any point to working it under embargo. > > You are correct here: you should assume that any LLM will give a similar > result to another person who asks a similar question. In other words, > LLM-discovered vulnerabilities should be considered already publicly known.
As a further data point backing up this theory: We’re seeing duplicate reports of the same issue found by multiple independent groups that use LLMs, within the embargo period. -- Clemens Lang RHEL Crypto Team Red Hat
