Who fixes the zero-days AI finds in abandoned software?
a day ago
- Anthropic's Claude Opus 4.6 found critical vulnerabilities in maintained open source projects, some undetected for decades.
- The bigger problem is abandoned software with no maintainers to patch, leaving a long tail of vulnerable servers.
- The author tested AI on abandoned software and found a critical RCE in minutes in an old PHP app, with a full proof of concept.
- Thousands of servers are exposed, often hosting sensitive data or usable as botnet infrastructure.
- Automated vulnerability discovery could yield hundreds of exploits quickly, shifting the economics of security.
- Guardrails on AI models are easily bypassed (e.g., by claiming defensive intent), and open-weight models further enable adversaries.
- Defensive acceleration requires someone to apply patches, which doesn't exist for abandoned software.
- Proposed drastic measures include mass disabling internet access to vulnerable servers; immediate advice: audit and migrate from unmaintained software.