you are viewing a single comment's thread
view the rest of the comments
[–] 0 points 3 months ago* (3 children)

NIST has already updated their CVE policies because of "record CVE growth".

This change is driven by a surge in CVE submissions, which increased 263% between 2020 and 2025.

Hmmmm, I wonder wtf happened during those years?

  • source
  • parent
  • hideshow 3 child comments
  • [–] 3 points 3 months ago (2 children)

    This change is driven by a surge in CVE * submissions *, which increased 263% between 2020 and 2025.

    Emphasis mine.

    Your link doesn't refute what I said. I acknowledged that there is an increase in bugs being found. That's inevitable when you add a new tool.

    My argument is that the framing is overblown. Sure, the submissions increased 263%, but how many of those are duplicate issues? Is it more like a 22% increase in actual bugs being found, with each being duplicated a dozen times of average? Big numbers are what get attention, but when you only frame an argument around the big number you lose a lot of the context.

    I recall either Lutris or Heroic games launcher actually seeing a (probably temporary) spike in bugs being found due to AI, but they were getting swamped by the same bugs being reported over and over in a short timespan. Each of those reports need to be looked over with the same amount of scrutiny, so flooding a repository with duplicate issues becomes a major drain on dev resources.

    Also, working in software myself, you always see a spike in issues when you first add a new test or check to your code. Then as you resolve those issues they drop back down. That's not that different from what we're seeing here with AI bug reporting

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 3 months ago (1 child)