May 21, 2026 (opens in new tab)
May 21, 2026 the 90 day disclosure policy is dead :: Himanshu Anand :: Threat Notes TLDR The 90 day responsible disclosure window was built for a world where bug finders were rare and exploit development was slow. That world is gone. LLMs have compressed both timelines to near-zero. I have seen it first hand, and so has everyone else paying attention. This post lays out why the old model is broken, with real stories, and makes one ask to the industry: treat every critical security issue as P0...
Read the original article