📊 Full opportunity report: The 90-Day Window Closed. Nobody Sent a Notice. on ThorstenMeyerAI.com — validation score, market gap, and execution plan.
TL;DR
The traditional 90-day window for responsible disclosure has closed without any notice from vendors or researchers. This change is driven by AI tools that enable rapid exploit development, raising concerns about vulnerability management and security response times.
The 90-day window traditionally used for responsible vulnerability disclosure has closed without any notices from affected vendors or security researchers, signaling a fundamental shift in cybersecurity dynamics.
On April 29, 2026, the Linux kernel patch for the Copy Fail vulnerability was made public, ending the four-week window since the patch was committed on April 1. Unlike previous practices, no security researcher or vendor issued a formal notice or warning during or after this period.
This development is driven by advancements in AI-driven vulnerability discovery, which enable attackers to analyze patches and develop exploits in minutes rather than days or weeks. As a result, the traditional 90-day period designed to give defenders time to patch and respond has been effectively nullified.
Experts note that this change undermines the assumptions underpinning responsible disclosure, such as the time needed to analyze patches and develop exploits, and the ability for defenders to deploy patches before attackers weaponize vulnerabilities. The shift indicates a move toward an environment where vulnerabilities are exploited immediately upon disclosure, rather than after a waiting period.
The 90-day window closed.
Nobody sent a notice.
The commit-monitoring window. The knowledge floor. And what Vercel and Canvas reveal about where the bugs actually live.
Copy Fail’s mainline patch landed April 1. Public disclosure was April 29. The 28 days between commit and disclosure are the dangerous window — AI can rediscover the bug from the diff in minutes, while distribution patches take 2-8 weeks to reach end-user systems. Three asymmetries compound: time, expertise, knowledge category. Defender disadvantage compounds across all three.
The patch is now the disclosure event.
Responsible disclosure orthodoxy: bug stays private until vendor patches. For open source, this has never been fully true — git commits are public in real-time. Copy Fail’s mainline patch landed April 1. Public disclosure was April 29. The 28 days between are the dangerous window.
fafe0fa2995a reverting the 2017 in-place AEAD optimization. Patch is now public.INSTANT
TREES
PUBLIC
AVAILABLE
SLOWLY

Vulnerability Management in Companies: Recognizing, assessing and eliminating vulnerabilities – with checklists, best practices and tools
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
“Please find a security vulnerability.”
No training required.
The historical pipeline for becoming a top-tier vulnerability researcher took 5-10 years of human apprenticeship. Kernel internals. Processor architecture. Exploit-mitigation-bypass craft. Decompiler-output reading. All baked into frontier model training data.
- CS degree with security specialization
- 3-5 years red team / CTF / firm experience
- 2-3 years senior research with reportable findings
- Tacit knowledge: kernel internals, decompiler output reading, exploit-mitigation-bypass craft
- Global pool: ~200-500 senior researchers per decade
- Apprenticeship: mentored by existing experts
- Frontier model API access ($20-200/month for individuals)
- One prompt: “Please find a security vulnerability”
- No security training required (Anthropic / AISI / CETaS verified)
- Tacit knowledge baked in from model training
- Pool of capable actors: millions globally
- Bottleneck: willingness to use it, not skill
The prompt Anthropic used to discover vulnerabilities with Mythos “essentially amounted to ‘Please find a security vulnerability in this program.'” Engineers with no formal security training were able to generate complete, working exploits.

Incident Response for Windows: Adapt effective strategies for managing sophisticated cyberattacks targeting Windows systems
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Memory safety isn’t where the breaches happen anymore.
Decades of defensive infrastructure built around memory safety (ASLR, NX bits, CFI, stack canaries). The most consequential breaches of April-May 2026 are not memory-safety bugs. They are trust-boundary failures at integration seams.
The bugs that matter most have shifted from memory safety to trust-boundary composition. OAuth scopes. SaaS-to-SaaS authentication. Multi-tier account models. Third-party app permissions. Environment variable handling. Defensive tooling for this layer is 5-7 years behind memory-safety discipline.
Defensive infrastructure for memory safety is 25+ years mature. Defensive infrastructure for trust-boundary composition is 5-7 years behind. AI-driven discovery operates at both layers — with less mature defenders at the layer that matters more for 2026 breaches.

Artificial Intelligence for Cybersecurity: How AI Detects Cyber Threats, Prevents Hacking, and Protects Your Data, Identity, and Smart Devices (AI Cybersecurity Mastery Series)
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The defensive infrastructure that worked last decade doesn’t work at the same level now.
Adaptation is necessary. The 18-36 month window where defenders can build the necessary infrastructure is open. Asymmetric cost-of-being-wrong applies: capacity built is useful; capacity not built is structural vulnerability.
+ SECURITY TEAMS
PUBLISHERS
POLICYMAKERS
EVERYONE ELSE
The 90-day window collapsed. The knowledge floor collapsed. The bugs moved layers. Three asymmetries compound. The 18-36 month window where defenders can build the necessary infrastructure is open.
vulnerability scanning tools for Linux
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Implications of the End of the 90-Day Disclosure Window
This shift has profound implications for cybersecurity, as it reduces the window for defenders to respond effectively. The ability for attackers to develop exploits almost immediately after patches are released increases the risk of widespread exploitation and compromises.
Additionally, the collapse of the knowledge floor—where even non-expert attackers can generate exploits—means that the barrier to exploiting vulnerabilities has lowered significantly. This could lead to an increase in attacks targeting not just kernel vulnerabilities but also trust boundary weaknesses in SaaS platforms and third-party integrations.
Overall, the end of the 90-day window signals a need to rethink traditional defense strategies, emphasizing real-time monitoring and proactive security measures over reliance on patch cycles and disclosure periods.
Evolution of Vulnerability Disclosure and AI’s Role
Since the early 2000s, the 90-day coordinated disclosure window has been a cornerstone of cybersecurity, balancing the interests of researchers and vendors. This period allowed vendors to develop patches before vulnerabilities could be exploited widely, based on the assumption that analyzing patches and developing exploits took significant time.
Recent advances in AI, exemplified by tools like Theori’s Xint Code, have drastically shortened this timeline. The April 2026 Linux kernel patch for Copy Fail was publicly disclosed on April 29, just 28 days after it was committed, and AI systems can now analyze such patches in minutes, not days. This technological shift has rendered the traditional window ineffective, as attackers can now rapidly weaponize vulnerabilities immediately after patches are released.
The Vercel and Canvas breaches highlight the new focus on trust boundary failures at the integration level, rather than memory safety bugs, emphasizing the changing nature of critical vulnerabilities in 2026.
“The 90-day window for responsible disclosure has effectively ended, driven by AI capabilities that allow exploits to be developed in minutes rather than weeks.”
— Thorsten Meyer
Unconfirmed Impact on Future Vulnerability Management
It remains unclear how widespread adoption of AI-driven discovery will influence future vulnerability management practices, or whether new frameworks will emerge to replace the 90-day window.
Additionally, the full extent of the shift in attack vectors—particularly at trust boundaries—has yet to be fully analyzed or publicly documented.
Next Steps for Security Practices and Policy Adaptation
Security organizations and vendors are likely to accelerate the development of real-time detection and response tools, moving away from reliance on patch cycles. Regulatory and industry standards may also evolve to address the new threat landscape, emphasizing proactive monitoring and immediate remediation.
Further research and case studies, like the Vercel and Canvas breaches, will inform best practices and help shape the future of vulnerability disclosure and management in an AI-augmented environment.
Key Questions
What does the end of the 90-day window mean for cybersecurity defenses?
It indicates that traditional defense strategies relying on patch cycles and disclosure periods may no longer be sufficient, requiring faster, real-time security measures.
How does AI accelerate exploit development?
AI tools can analyze patches and code commits in minutes, enabling attackers to develop exploits immediately after vulnerabilities are disclosed.
Are vendors and researchers still responsible for disclosure?
Responsibility remains, but the effectiveness of responsible disclosure practices is challenged by AI’s ability to bypass traditional waiting periods.
What vulnerabilities are most at risk now?
Trust boundary failures, such as OAuth misconfigurations and SaaS-to-SaaS authentication issues, are increasingly targeted, as they are less protected by memory-safety defenses.
Source: ThorstenMeyerAI.com