OCaml Maintainer: Exploits Now Arrive Within 10 Minutes of a Bug Rumor
Cambridge professor and OCaml maintainer Anil Madhavapeddy reports attackers probing OCaml infrastructure for exploits within about ten minutes of a security issue being shared for discussion, before any patch or release.
What it is
A post by OCaml core maintainer Anil Madhavapeddy describing how quickly attackers now react once a security issue is even discussed, based on real traffic seen on OCaml project infrastructure.
What it does
Documents a shift from the old norm of a few days to a week before exploit attempts appear, down to roughly ten minutes after a bug is merely rumored or discussed, before any patch exists.
Why it matters
If discussion alone triggers exploitation attempts, coordinated disclosure timelines built around days-to-patch assumptions are obsolete, and maintainers of any language ecosystem, not just OCaml, need to rethink how they talk about unpatched issues in public.
How to use it
Read the full account at anil.recoil.org and reconsider whether your project discusses vulnerabilities in public channels before a fix ships.