
Last July, Google revealed a fascinating case that may change how we think about vulnerability disclosure. Big Sleep, an AI agent jointly developed by Google DeepMind and Project Zero, successfully discovered a memory corruption vulnerability in SQLite (CVE-2025-6965) and helped researchers report and patch it before attackers could weaponize it. What makes the case even more remarkable is how little information the research team had to begin with. They only knew one thing: someone might be preparing to exploit an unknown vulnerability in SQLite. But no one knew what the vulnerability was—or where it was hiding. Using this limited threat intelligence, Big Sleep analyzed the code, reasoned about potential locations, and ultimately identified the vulnerability, helping researchers validate the finding and complete the disclosure process. The case raises a bigger question: If AI can dramatically reduce the time it takes to find vulnerabilities, is it time to rethink a vulnerability disclosure system that has been in place for more than a decade? For years, the security community has relied on a shared framework: researchers privately notify vendors, give them time to fix the vulnerability, and only then disclose the details publicly. Project Zero’s 90-day disclosure policy is one of the most influential examples of this approach. But this system rests on an important assumption: Finding vulnerabilities is slow, difficult, and expensive. AI is rapidly changing that assumption. Big Sleep has shown that AI can use limited clues to reason its way toward the location of a vulnerability. And when publicly available information can itself become a clue for AI to identify new vulnerabilities, are today’s disclosure practices still appropriate for the AI era? Does the disclosure period still matter? And what information should be disclosed—and when? These are at the heart of James Forshaw’s HITCON Keynote, Vulnerability Disclosure in the Age of AI. 🌟 Vulnerability Disclosure in the Age of AI — James Forshaw 【🪧 About the Keynote】 Known for his research into Windows logic vulnerabilities and sandbox escapes, James Forshaw is also the creator of open-source security tools widely used by researchers across the industry. More importantly, he isn’t simply an outside commentator on vulnerability disclosure. He is a practitioner who has been part of Project Zero’s vulnerability disclosure policy in action. In this keynote, James will look back at the history of vulnerability disclosure, examine how AI is changing the assumptions behind today’s disclosure practices, and ask whether we need to rethink the social contract that has shaped the global security industry for years. If you care about vulnerability research, threat intelligence, AI Security, or how AI will reshape the pace of offense and defense, this is a keynote you won’t want to miss. Because this isn’t just a discussion about how AI finds vulnerabilities. It’s about what happens to vulnerability disclosure when AI changes how fast we can find them. And that may be the next turning point for the security industry. Ticket information and registration: https://hitcon.kktix.cc/events/hitcon-2026 #HITCON2026 #HITCON #HackerConference #CyberSecurity #AISecurity
Post summary
Big Sleep, a Google DeepMind AI agent, identified a memory‑corruption flaw (CVE‑2025‑6965) in SQLite and assisted researchers in patching it before it could be weaponized, prompting a discussion on whether traditional vulnerability disclosure timelines remain appropriate in an AI‑driven era.



