GNOME is changing its security-report handling process after volunteer maintainers were flooded with AI-assisted vulnerability submissions. For issues reported on or after August 1, 2026, the project will reduce its disclosure deadline from 90 days to 30 days, with security lead Michael Catanzaro saying the shorter window better reflects GNOME’s workflow because valid issues are typically fixed within one to three weeks, while others often remain unresolved.
GNOME said it will apply the same rules to AI-assisted and human-written reports, but projects that prohibit AI-generated content will no longer receive forwarded reports when submissions contain AI- or LLM-generated findings; those issues will instead be closed in the tracker, though maintainers may still be notified. Catanzaro, who has overseen GNOME security issue tracking since 2020 with Red Hat support, also said he will stop tracking newly reported issues in November 2026 and fully step away by December 1 unless an experienced community successor is found.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Help Net Security reported that Catanzaro plans to finish the role by 2026-12-01 unless a successor is found.
Catanzaro said he will stop tracking newly reported GNOME security issues on 2026-11-01 and is seeking experienced community members to take over the role.
GNOME said it will shorten its vulnerability disclosure deadline from 90 days to 30 days for issues reported on or after 2026-08-01. The change was described as better matching GNOME's workflow because valid issues are usually fixed within weeks.
GNOME announced changes to its security-report process in response to a steady flow of AI- or LLM-generated vulnerability submissions. The project said it will apply the same rules to AI-assisted and human-written reports, while changing how AI-generated findings are forwarded to projects that prohibit such content.
Michael Catanzaro said he has managed GNOME's security issue tracking since November 2020, with support from Red Hat.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcelinuxsecurity.com
Open sourcehelpnetsecurity.com
Open sourcephoronix.com
Open sourceblogs.gnome.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.