frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Critical CVE issued for hallucinated SQLite vulnerability

https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
107•ymir_e•55m ago

Comments

inigyou•39m ago
This is going to be fun for organizations that are mandated to patch all CVEs, isn't it?
ymir_e•28m ago
This was my first thought, this could be terrible if used offensively.

The best defense I can imagine is to have an agent reproduce the issues before a human sees it, but even that will cost money.

lucideer•28m ago
I'm very curious what organisations would have such a policy. I can't imagine it being viable for any size of org without significant self-deception (or banning the use of all open source at which point CVEs are moot anyway).
SirFatty•26m ago
ITAR
lucideer•14m ago
ITAR has no such hard requirements. Might be some orgs that tell themselves they're attempting this under ITAR but they're not doing it in any comprehensive way.

The only thing within ITAR that I'm aware of concerning itself with software supply chain is SP 800-218 requirements & that's just a load of open-to-interpretation weasel words about having CVE detection & automations in place & some defined plans for reducing the number of vulns. Pretty sure that component of it is even eligible for self-assessment.

clbrmbr•24m ago
Many orgs (esp w ISO27000) have a vulnerability management policy that involves patching at least critical CVEs within a short timeline. Tools like trivvy make it possible to do the scans…
lucideer•2m ago
I've been in such an org, & I've led initiatives to set up automated detection at very large scale. We started by issuing tickets to teams to resolve CVEs within varying timelines - ranging from a 24hr fix to 6 months - connected to the CVSS score. It wasn't viable.

- Firstly, you quickly realise how irrelevant CVSS scores are - initiatives like First's EPSS are designed to fix this but they aren't there yet

- Secondly, you need to begin implementing localised heuristics to determine exploitable code paths. This has generally been incredibly difficult to do reliably - LLMs have started to make it easier, but it's expensive.

- Lastly, you need to factor in consideration of actionable remediation pathways. A dependency upgrade for critical infrastructure might contain breaking changes that take months to fix, or two competing CVEs might be present in interdependent versions of transitive dependencies in your sbom tree.

Most orgs aren't applying any of the above three filters to reduce their CVE remediation burden, & even if they are, it's still too high to make zero a viable target.

In reality, most orgs aren't doing comprehensive detection to begin with - if you haven't discovered all of your CVEs, your remediation burden is going to be a lot more manageable.

anygivnthursday•15m ago
If I remember correctly, we had to patch or provide justification for CVEs flagged by tools like AWS Inspector for SOC2 as well.
YeahThisIsMe•11m ago
So you didn't have to patch all of them.
whatevaa•25m ago
Those organizations will have to adapt to new reality, ie, that some CVEs are not real.
ape4•25m ago
Create the referenced but non existent file and then fix it /s
cleansy•21m ago
All organisations also have exceptions to policies. This one would be one
smitty1110•18m ago
It’s honestly not great. The security guys are completely exasperated at my job, we’re wasting time having with these. You take the scam really, investigate for a bit, write up a DNF with justification, they go and up date records, and we all just kinda hope that someone updates the scans so it stops showing up.

Something is going to give, and I suspect that the optimistic open filling is going to get canceled.

ChrisMarshallNY•32m ago
The problem with this kind of thing, is that it reduces the S/N (Signal-to-Noise) ratio, so weeding out the legit CVEs becomes a lot more difficult.

But, on the other hand, I do know that LLMs have been discovering a lot of legit CVEs, and I will lay odds that the blackhats are leveraging them to the max.

ymir_e•16m ago
It seems like we're in a transition period where AI will eventually make all software much more secure than it ever was.

In this period every part of offense and defensive cyber security changes quite rapidly.

Noisy CVEs will probably lead to agents verifying vulnerabilities before humans review them.

The problem with agent reviews from what I can think of is:

- cost to use LLMs to review things

- not necessarily easy to plug-and-play in repos: (domain knowledge + how to look for vulnerability specifically for the stack)

- especially with anthropic: able to use models defensively, without hitting guardrails.

The last one is the most interesting one to me. How does the AI providers know if you're a "good or bad" guy? And does it matter if open source is catching up?

We're in a kind of cyber arms race wether we like it or not.

rghammt•4m ago
Currently we either get AI promo vulnerability dumps like from Chrome with pretty graphs that no one checks or false positives.

Where is this one now that was hyped everywhere?

https://news.ycombinator.com/item?id=49133889

The GitHub submitter could no longer reproduce the issue and the LKML post has no replies:

https://lore.kernel.org/all/CALCETrXbj__SFQMzPZhES5y6-sh4np-...

dvh•30m ago
You're absolutely right...
mlvljr•28m ago
Honest take, this is a critical CVE.
Spide_r•22m ago
Somewhat related: https://sqlite.org/cves.html
Ekaros•20m ago
Not validating submissions seems like avenue for massive attack. Flood the whole system with endless false reports. Thus making it significantly less reliable.
insanitybit•9m ago
This is what the Linux kernel is currently attempting since becoming a CNA.
masklinn•1m ago
That is exactly why many big projects are migrating to becoming CNA, so that randos can’t get assigned unqualified CVEs which nobody has looked at or validated.

Apparently RedHat is a CNA of last resort, so it might be possible to get your project under Redhat’s scope and go through them without having to be a CNA yourself.

progval•19m ago
> All advisories in this repo seem AI generated when testing them with Gptzero

I pasted this blog post from "Analysis Matrix" to the end in Gptzero, and it also says the blog post was AI-generated (71% chance of AI, 29% chance of AI-Human mix).

sabot90260•4m ago
A critical rating on a vuln that doesn't exist is wild. The triage cost still lands on the maintainers.
throwa356262•4m ago
In the mean time, my very real vulnerability reports are not acknowledged because maintainers are busy handling this kind of nonsense.
trueno•1m ago
just ran this article that ran a cve through gptzero.. through gptzero

GPTZero AI Detection

Model 4.8b

We are moderately confident this text is a mix of AI and human

63/88Sentences likely AI generated

Inside An AI TikTok Shop Slop Factory That Shills Supplements Recalled by FDA

https://www.404media.co/inside-an-ai-tiktok-shop-slop-factory-that-shills-supplements-recalled-by...
1•bookofjoe•48s ago•0 comments

Show HN: Runthru – open-source Interactive Demos

https://github.com/marktolson/runthru
1•marktolson•1m ago•0 comments

Augmenting Long-Term Memory

https://augmentingcognition.com/ltm.html
1•olexsmir•2m ago•0 comments

Most Likely Future Filter: World Govt

https://www.overcomingbias.com/p/most-likely-future-filter-world-govt
1•surprisetalk•2m ago•0 comments

GitHub/gh-stack: GitHub Stacked PRs

https://github.com/github/gh-stack
1•sshah•5m ago•0 comments

Two Overlapping Circles

https://lemurintheattic.mataroa.blog/p/two-overlapping-circles/
1•xyztenet•9m ago•0 comments

WebExt Ship Kit: Build Once, Validate for Chrome, Edge, and Firefox

https://github.com/blueyferg/webext-ship-kit
1•clevercreator•10m ago•0 comments

IBM Claims Quantum Advantage with New Validation Techniques

https://spectrum.ieee.org/ibm-verifiable-quantum-advantage
1•Schlagbohrer•11m ago•1 comments

Show HN: Argot, a Rust AI guardrail based on your codebase AST patterns

https://argot.tmonier.com/
2•damienmeur•11m ago•0 comments

Promises, Kept

https://www.anuclei.com/blog/promises-kept-building-multisynapse
1•jequals5•13m ago•0 comments

VibeMenu – a local macOS menu-bar dashboard for Claude Code and Codex

https://github.com/Kirill-Chistov/VibeMenu
1•KirillChistov•14m ago•0 comments

GLM-5.3 Soon

https://github.com/zai-org/z-ai-sdk-java/commits/glm-5.3
3•OsamaJaber•15m ago•0 comments

Spriteloom – local AI pixel-art generator plugin for Aseprite

https://github.com/vkarach/spriteloom
1•vkarach•17m ago•0 comments

FlakeAudit, a CLI for evaluating Nix flake SBOMs against org policies

https://determinate.systems/blog/introducing-flakeaudit/
1•biggestlou•18m ago•0 comments

SecurityPolicy restrictions unenforced by default sandbox back end in PraisonAI

https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5r6c-gj4g-r697
1•LHMisme•19m ago•0 comments

Linux 7.3 Adding Support for MCTP-over-USB v1.1

https://www.phoronix.com/news/Linux-7.3-MCTP-Over-USB-1.1
1•Bender•19m ago•0 comments

What You'd See During an AI World War [video]

https://www.youtube.com/watch?v=Gw_hnD7m00M
1•freakynit•19m ago•0 comments

VictorTaelin/Nanoproof

https://github.com/VictorTaelin/nanoproof
1•surprisetalk•23m ago•0 comments

Pavel Durov – Communication Technology and the Struggle for Freedom [video]

https://www.youtube.com/watch?v=1Yq_5aDdJ24
1•rzk•24m ago•0 comments

The AI bubble is popping; we just don't know it yet

https://www.theregister.com/ai-and-ml/2026/08/03/the-ai-bubble-is-already-popping-we-just-dont-kn...
13•Bender•25m ago•4 comments

ERP and MES Integration for US Pharma Manufacturers

https://geekyants.com/blog/erp-and-mes-integration-for-us-pharma-manufacturers-a-roadmap-to-achie...
2•varda_62892•27m ago•0 comments

The Grass Is Greener

https://www.bassfinity.com/blog/the-grass-is-greener-reading-summer-vegetation
1•jequals5•27m ago•0 comments

Show HN: Ccbeam – Teleport your Claude Code sessions to and from the cloud

https://github.com/sahilmahendrakar/ccbeam
2•smahendrakar•29m ago•0 comments

North Korea NullReceiver Hides Malware in NPM

https://opensourcemalware.com/blog/nullreceiver-dprk-c2-technique
2•6mile•29m ago•1 comments

How Europeans are struggling to balance work and personal time

https://www.euronews.com/business/2026/08/03/how-europes-working-day-is-increasingly-encroaching-...
1•rustoo•32m ago•0 comments

Show HN: Analytics Tycoon: I built an Age of Empires like game for data

https://analytics-tycoon.netlify.app/
2•12ian34•33m ago•0 comments

Ask HN: Future of junior level software developers outside US and UK

1•shashubansal247•34m ago•0 comments

Valetudo Camera Streaming (FOSS for Vacuum Robots)

https://github.com/Hypfer/Valetudo/discussions/2547
1•gempir•34m ago•0 comments

Before Plug and Play Worked

https://comuniq.xyz/post?t=1488
1•01-_-•35m ago•0 comments

Show HN: AgentCodeGUI – Multi-Account Desktop GUI for Claude Code and Codex

https://github.com/UnrealFactory/AgentCodeGUI
1•asdsa112•36m ago•0 comments