Everyone that manages security reports for Open Source projects have been getting a higher workload because of AI. Both real reports and just slop - reports including vulnerabilities in code that doesn't exist. For some, this is becoming a denial of service attack, with developers having to spend valuable, and in some cases unpaid, time to sort out what's real and may be a vulnerability.

Jarek Potiuk, member of The Apache Software Foundation will talk about this on the GVIP Summit Wednesday Jan 28th in Brussels. We still have a few seats available - but hurry up to register!

gvip-project.org

0

If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/Oej/statuses/115926874720228640 on your instance and quote it. (Note that quoting is not supported in Mastodon.)