you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 3 months ago (5 children)

which is problematic considering their sloppy AI slop never had so many bugs as it does now.

Honestly, it's the opposite: AI is exposing so many bad security bugs that they are having a hard time keeping up.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 2 points 3 months ago (4 children)

    That's overblown. Yes, people are finding security bugs with AI, you will always get that when adding new tests with a different perspective. But the "having a hard time keeping up" come from the AI constantly spamming devs with duplicate issues.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 0 points 3 months ago* (3 children)

    NIST has already updated their CVE policies because of "record CVE growth".

    This change is driven by a surge in CVE submissions, which increased 263% between 2020 and 2025.

    Hmmmm, I wonder wtf happened during those years?

  • source
  • parent
  • hideshow 3 child comments
  • [–] 3 points 3 months ago (2 children)

    This change is driven by a surge in CVE * submissions *, which increased 263% between 2020 and 2025.

    Emphasis mine.

    Your link doesn't refute what I said. I acknowledged that there is an increase in bugs being found. That's inevitable when you add a new tool.

    My argument is that the framing is overblown. Sure, the submissions increased 263%, but how many of those are duplicate issues? Is it more like a 22% increase in actual bugs being found, with each being duplicated a dozen times of average? Big numbers are what get attention, but when you only frame an argument around the big number you lose a lot of the context.

    I recall either Lutris or Heroic games launcher actually seeing a (probably temporary) spike in bugs being found due to AI, but they were getting swamped by the same bugs being reported over and over in a short timespan. Each of those reports need to be looked over with the same amount of scrutiny, so flooding a repository with duplicate issues becomes a major drain on dev resources.

    Also, working in software myself, you always see a spike in issues when you first add a new test or check to your code. Then as you resolve those issues they drop back down. That's not that different from what we're seeing here with AI bug reporting

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 3 months ago (1 child)