Maybe I'm projecting my own biases ;-)
So, knowing that bad actors have an unending river of cheaply acquired zero days, the best response is to publish them so that maintainers also have access to them. Existing methods of slow disclosure cannot keep up with the AI firehose.
It’s ugly, but it will force needed change. A thorough AI red team effort is the lowest bar of releasing software responsibly in this day and age.
All this is doing is making the AI firehose worse.
I’m onboard with this being suboptimal. But as someone who has filed >10 significant disclosures in the last month resulting from reviewing my codebase and had exactly zero responses, I can relate to the decision.
I do wonder though: if you can tell the AI to search for vulns, can't you also tell it to contact the right maintainer for each one found?