Vulnerability Research Is Cooked: “You can't design a better problem for an LLM agent than exploitation research”

https://simonwillison.net/2026/Apr/3/vulnerability-research-is-cooked/#atom-everything

Hope you have redundant offsite archived backups.

#jgshare

Vulnerability Research Is Cooked

Thomas Ptacek's take on the sudden and enormous impact the latest frontier models are having on the field of vulnerability research. Within the next few months, coding agents will drastically …

Simon Willison’s Weblog
@jgordon Looking at everyday backup options, especially for companies and organizations, users are cooked.
@jgordon Files stored locally or on a server can be backed up, also off-site. There are some good solutions for this, though not many. And everything has its price. «Write-only», however, is a topic of its own.
@jgordon For all other data, backup is often difficult or even impossible. Most cloud SaaS services, i.e., ost of the software used today, do not offer built-in backup options at all. It starts with e-mail. How do you back up all e-mail for all users stored in Gmail, for example? And how do you back up, for example, GoogleDrive / Google Docs, a support ticket system or a cloud CRM?

@jgordon For most online services, you are lucky if you can initiate a manual export, but that is not a backup. For actual backups, meaning automatic backups, you have to rely on hacks used by third-party «backup services». And even if you have up-to-date backups: How is the restore carried out if needed?

Finally: What happens if a provider you depend on gets hacked, destroyed etc.?