Generative AI Creates Challenges in Cybersecurity with Fake Vulnerability Reports
Generative AI is increasingly being used to create fake vulnerability reports, posing significant challenges for the cybersecurity industry. A recent incident involved a batch of supposed SQLite vulnerabilities that were found to be technically bogus. These reports, which appeared in the National Vulnerability Database (NVD), were identified as likely AI-generated by JFrog, a software supply chain security company. The fake reports included high CVSS scores, misleadingly suggesting severe security issues. The U.S. National Institute of Standards and Technology (NIST), responsible for managing the NVD, has been struggling with a backlog of unprocessed CVEs, exacerbating the issue. This backlog has grown significantly since 2024, reaching over 27,000 unprocessed CVEs by the end of 2025. The lack of mandatory verification steps in the current system allows fake advisories to enter databases, wasting resources and potentially diverting attention from real security threats.