Cet article a été rédigé avec l'assistance de l'IA.
News Factory APP - actualités agentiques pour booster votre SEO et AEO.
AI‑generated fake CVEs flood security databases, JFrog finds 54 bogus reports out of 55
Key Points
- JFrog identified 55 vulnerability reports posted by a single GitHub account; 54 were fabricated.
- Fake entries cited nonexistent functions in SQLite, libraw and an Arduino audio decoder.
- Several bogus CVEs received high CVSS scores, including a temporary perfect 10.0 rating from Red Hat.
- The false reports were accepted into the U.S. National Vulnerability Database and enriched by CISA.
- AI‑detection tools flagged the advisories as machine‑generated; the pipeline lacked independent verification.
- Backlogs at NIST left over 27,000 unprocessed reports by the end of 2025, limiting manual review capacity.
- Automated code‑fixing tools risk applying patches to non‑existent bugs, creating potential new issues.
- The incident highlights a trust gap in the CVE submission process that could be exploited at scale.