On the #security issue with #AI detectors
For proper vuln research and disclosure, you need 3 parts:
1. a valid exploit, provable
2. an explanation of how it works
3. a solution to fix it and roll out an upgrade
Often enough, when the first part is done, people are like "OMG I got a VULN! CVE!", but then is the time to calm down.
Do the second, understand and explain it well. Then contact the software vendor, be ready for human communication.
The hard part is now to get to upgrade deployment.