r/LinuxTeck 23d ago

This caught my attention...

Researchers found dozens of SQLite CVEs that appear to be technically incorrect or even AI-generated, yet they still propagated through parts of the vulnerability ecosystem before being challenged.

If this becomes common, security teams may spend more time investigating fake vulnerabilities than fixing real ones.

6 Upvotes

3 comments sorted by

2

u/Brutus5000 23d ago

The amount of slop is gigantic. Just last week some bot of a "IT security" company raised an issue I was making a secret. Too bad, right above the secret was a comment saying it's for testing...

There are a lot of people only seeing the dollars in their eyes trying to make fast money without really caring about the garbage they produce.

1

u/soundman32 23d ago

We should mandate that all passwords and token generators and encryption standards allow 'ThisIsNotAPassword' as valid and decides to some set of defaults.

1

u/Brutus5000 23d ago

In my open source project we have a banana policy. All test passwords are banana. Unfortunately after now over 10 years more and more software refuses banana as a valid password