AI-Generated Fake Vulnerabilities Flood U.S. National Database, Raising Security Concerns
Security firm JFrog has identified a significant issue with AI-generated fake vulnerabilities being submitted to the U.S. National Vulnerability Database (NVD). The firm discovered that out of 55 vulnerability reports posted by a new GitHub account, 54 were fabrications. These reports included false claims of severe memory bugs in SQLite, with some being rated as high as 9.8 in severity. The fake vulnerabilities were generated by AI and managed to reach the NVD, where they were marked as critical. This situation highlights a growing problem where AI-generated content is being trusted without sufficient verification, leading to potential security risks as AI coding agents may attempt to fix non-existent issues.