aiminute. ← All AI news
Research AI Minute Newsroom 2026-08-03

54 of 55: AI-written fake CVEs fooled the US vulnerability database

54 of 55: AI-written fake CVEs fooled the US vulnerability database

Security firm JFrog examined 55 vulnerability advisories that a single GitHub account published within four days and found 54 were fabricated — apparently by an AI. Six 'critical' SQLite flaws cited code that doesn't exist (one pointed to line 3,575 of a 2,706-line file), and none of the proof-of-concept exploits actually worked. The US National Vulnerability Database still rated them critical, and CISA's reviewers concurred.

Why it mattersCompanies prioritize patching based on CVE severity scores, yet nothing in today's pipeline requires anyone to reproduce a bug before it is certified as critical. AI has made plausible-looking fake advisories nearly free to produce — so security teams now have to verify the verifiers.

✓ Verified · 2 sources

WhatsApp X Telegram
Read in the app — free, in 9 languages

Related stories

A model learned to write without the method that trains every AI.
2026-10-06
Mathematicians cracked five open problems using an ordinary chat box.
2026-10-05
Untuned models solved agent tasks their polished versions could not.
2026-10-04
Pretraining on everyday photos got a model to 70% on a reasoning test.
2026-10-04
An AI trained for $8,000 beat Stratego's greatest player.
2026-10-03