Vulnerability Reports Are Not Special Anymore
Summary
The author argues that vulnerability reports are no longer special in 2026, claiming LLMs enable attackers and defenders to find issues with similar efficiency. The bottleneck has shifted to triage and signal-to-noise, necessitating new practices like running LLM analysis in CI and rethinking confidentiality. The piece also highlights OSS funding and the evolving relationship between researchers and maintainers.