Security teams and bug bounty programs are confronting a rise in AI-generated vulnerability submissions that appear technically credible but often cite nonexistent functions, commits, CVEs, attack paths, or impacts without reproducible evidence. The low cost of producing these reports shifts substantial verification work to expert triagers; curl, Node.js, and Hibernate have been cited as affected projects. HackerOne and Bugcrowd are responding with reputation, workflow, and machine-learning-based filtering, while valid AI-assisted discoveries still require concrete data-flow analysis and a working proof of concept, as demonstrated by CVE-2024-10099 and CVE-2024-10131.
Chrome's Security Team has published procedures for an anticipated influx of AI-generated reports in its internal processes and Vulnerability Rewards Program. It directs teams to fix S0 issues within one week and S1 issues within four weeks, initially handle reports lacking proof-of-concept code as security bugs, define security boundaries in SECURITY.md, and use invalid-report decisions as AI training and evaluation data. AI-generated findings receive the same disclosure treatment as human submissions, with publication 30 days after a fix, while the guidance also covers duplicates, disabled features, external dependencies, and rapid mitigations such as replacing renderer-reachable DCHECK assertions with CHECK assertions.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
curl creator Daniel Stenberg publicly characterized the growth of LLM-generated false vulnerability reports as “Death by a Thousand Slops.”
CVE-2025-59536 was identified as a code-injection vulnerability in Claude Code versions before 1.0.111. It could enable code execution from a project before the user confirmed the trust dialog when Claude Code was launched in an untrusted directory.
Vulnhuntr identified CVE-2024-10131, a code-injection vulnerability in RagFlow. The add_llm function dynamically created classes using the user-controlled req['llm_factory'] value without validation.
Protect AI's Vulnhuntr identified a stored cross-site scripting flaw in ComfyUI, tracked as CVE-2024-10099. The issue allowed an attacker to upload HTML containing an XSS payload through /api/upload/image that executed when viewed through /view, subject to user interaction.
Bugcrowd applied manual playbook-based analysis and machine-learning assistance to process incoming vulnerability reports amid a reported increase of roughly 500 submissions per week.
HackerOne launched Hai Triage, using AI agents to identify noise and duplicates and prioritize possible threats, with humans validating and escalating results.
Node.js increased the minimum HackerOne reputation score required of researchers in response to triage pressure. Its security team also began examining an LLM-assisted triage workflow combining rule-based filtering with human review.
The CycloneDX project fully closed its GitHub bug bounty program, citing a flood of reports that were almost entirely AI-generated false submissions.
The Chrome Security Team published guidance for handling AI-generated vulnerability reports from external VRP submitters and internal AI tooling. It directs teams to initially treat reports without a PoC as full security issues and sets remediation targets of one week for S0 and four weeks for S1 bugs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.