eva hill

ramblings

thoughts are fleeting and ever changing, never carved in stone

The vulnerability bottleneck has moved

finding bugs is easy, fixing them is hard

Updated june 2026

A spring of npm supply chain attacks and back-to-back Linux kernel exploits, and the uncomfortable thing they have in common. AI hasn't made attackers smarter so much as made finding bugs cheap enough to run in a loop overnight pushing existing systems of disclosure and open source maintainers to their limits.