LLMs hugging the CVE system to death
A GitHub account published 55 security advisories for SQLite, 54 of which were fabricated and one contained a real bug, according to a JFrog audit. The NIST National Vulnerability Database (NVD) regis…
A GitHub account published 55 security advisories for SQLite, 54 of which were fabricated and one contained a real bug, according to a JFrog audit. The NIST National Vulnerability Database (NVD) regis…
The White House has finalized a voluntary framework for cybersecurity testing of advanced AI models, allowing federal agencies access to frontier AI systems for up to 30 days before public release, do…
JFrog reported that six SQLite CVEs published by a new GitHub repository were fake, likely AI-generated, with CVSS scores ranging from 9.8 to 7.5, and none described a reproducible vulnerability. The …
JFrog's security research team found that 54 of 55 SQLite advisories filed as critical CVEs were fabricated by an AI language model, including CVE-2026-51302, which was withdrawn four days after publi…
The US Cybersecurity and Infrastructure Security Agency (CISA) published the Open Source Software: Security Principles and Practices guide, offering federal agencies recommendations for managing open …
JFrog security researchers found that a batch of SQLite vulnerability advisories published by GitHub user programmervuln in the repo cveadvisory- are AI-generated 'LLM slop' and do not describe real v…
Thermo Fisher Scientific patched a high-severity vulnerability (CVE-2026-17583, CVSS 8.2) in its Applied Biosystems DNA analysis software that allowed anyone with server access to alter evidence files…
On 15 May 2026, the Bank of England, the Financial Conduct Authority and HM Treasury warned that frontier AI models carry serious cyber and operational resilience implications for regulated firms and …
A bipartisan House bill introduced on July 23, 2026, by Rep. Ted Lieu (D-Calif.) and co-sponsored by Rep. Nathaniel Moran (R-Texas) would require developers of the most powerful AI systems to maintain…
CISA has published the 2026 Minimum Elements for a Software Bill of Materials, replacing the 2021 baseline with a version that requires component hashes, adds license and generation-context fields, an…
The US government missed the August 1, 2026 deadline to establish a classified benchmarking framework for evaluating frontier AI models' cyber capabilities, as required by President Trump's June 2, 20…
President Trump signed Executive Order 14409 on June 2, 2026, and its August 1 deadline has passed, establishing a classified federal cyber review process for AI models deemed 'covered frontier models…
The Cybersecurity and Infrastructure Security Agency (CISA) published a guidebook Thursday for federal agencies on managing security risks with open-source software (OSS), including recommendations fo…
OpenAI CEO Sam Altman will meet White House chief of staff Susie Wiles, National Cyber Director Sean Cairncross, and science adviser Michael Kratsios on July 30, 2026, to discuss voluntary government …
Attackers are exploiting a static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), according to CISA. The flaw, reported by Jimi Sebree of Horizon3.ai, invo…
KEVIntel CEO Ryan Dewhurst reports that the company's global honeypot sensor network, AI triage, and human verification lab confirm exploitation of vulnerabilities not yet listed in CISA's Known Explo…
CISA's Binding Operational Directive (BOD) 26-04 shifts federal vulnerability management from uniform patching to risk-based remediation, with deadlines ranging from three days for high-risk vulnerabi…
The Federal Communications Commission added advanced robotic devices and connected power inverters to its Covered List on Tuesday, effectively banning new imports of foreign-made robots and inverters …
AI advances have broken the traditional security model of patching vulnerabilities fast enough, according to a new analysis. Anthropic's Mythos, though not publicly available, demonstrates that LLMs m…
AI-discovered software vulnerabilities are surging at roughly twice last year's rate, but almost none are being exploited, according to a VulnCheck report. Of 1,061 vulnerabilities attributed to AI-as…