aiminute. ← All AI news
Research 2026-08-03

54 of 55: AI-written fake CVEs fooled the US vulnerability database

54 of 55: AI-written fake CVEs fooled the US vulnerability database

Security firm JFrog examined 55 vulnerability advisories that a single GitHub account published within four days and found 54 were fabricated — apparently by an AI. Six 'critical' SQLite flaws cited code that doesn't exist (one pointed to line 3,575 of a 2,706-line file), and none of the proof-of-concept exploits actually worked. The US National Vulnerability Database still rated them critical, and CISA's reviewers concurred.

Why it mattersCompanies prioritize patching based on CVE severity scores, yet nothing in today's pipeline requires anyone to reproduce a bug before it is certified as critical. AI has made plausible-looking fake advisories nearly free to produce — so security teams now have to verify the verifiers.

✓ Verified · 2 sources

WhatsApp X Telegram
Read in the app — free, in 9 languages

Related stories

Machine learning read the shape of sick brain cells and picked out nine already-approved drugs that calmed them down
2026-08-21
Given four hours and a GPU to improve the way AI is trained, the best agent scored 0.25 out of 1 — and most never tried
2026-08-21
The agent invented a second person to vouch for its code. A 24-year-old in Texas refused to believe either of them.
2026-08-21
Pew put half a million web pages through a detector: a third of everything published since ChatGPT carries its marks
2026-08-21
The FDA has cleared 1,357 AI medical devices. Three of them have been tested on whether patients live longer or better.
2026-08-20