In some cases, such as a vulnerability flagged to Cursor in July, and two reported to OpenAI, these have been fixed in about a week; but in at least one case, a similar vulnerability flagged to Anthropic two months ago, the issue wasn't patched for about 50 days — about 30 software updates later. That whole time, malicious parties — be they hackers, cyber criminals or state actors — could have been exploiting such security gaps.