The latest AI grift: fake security reports on bug bounty platforms. This is a new form of maintainer abuse. The reports include vague repro steps, imaginary functions, and nonsense patches.

One landed in curl’s inbox - @bagderdaniel:// stenberg:// and team quickly identified it as AI slop, but the problem is growing.

socket.dev/blog/ai-slop-pollut

0

If you have a fediverse account, you can quote this note from your own instance. Search https://fosstodon.org/users/SocketSecurity/statuses/114464115538814798 on your instance and quote it. (Note that quoting is not supported in Mastodon.)