LLM-generated CVE reports are polluting security databases
Someone is flooding the National Vulnerability Database with fake SQLite vulnerabilities written by language models, and it is breaking actual security work.
From the notebook
7 notes on this topic.
Someone is flooding the National Vulnerability Database with fake SQLite vulnerabilities written by language models, and it is breaking actual security work.
Fifteen years of a compartmentalised desktop OS, zero remote code execution bugs. The paper tracking every public Qubes vulnerability is out.
A ransomware gang says they got into Tata's systems and grabbed confidential files from Apple and Tesla. The supply chain question nobody wants asked.
The Arch Linux team spent the weekend cleaning up more than 1,500 malware-laden packages from the AUR. The scale is what surprised me.
The Arch User Repository just had 400 packages backdoored. The attack vector was not clever. It was obvious, predictable, and it worked anyway.
YAML, TOML, and JSON parsers can run arbitrary code during deserialization. Most dependency scanners miss them entirely.
PHP's dependency manager is rolling out cryptographic signatures. The timing matters more than the tech.