AI slops from Eve
oss-security moderator Solar Designer approved three AI-generated vulnerability reports from automated security researcher Eve, sparking debate over AI slop on the list.
oss-security moderator Solar Designer approved three posts submitted by Eve, described as an 'automated security researcher', noting they lacked Date headers and arrived on the list server on September 9. He expressed uncertainty about their value but suggested they may have historical significance as early examples of AI-generated security reports at the dawn of AI security research. The post is meta-commentary on AI-generated content reaching a vulnerability disclosure mailing list rather than a specific vulnerability disclosure itself.
Re: AI slops from Eve
oss-security commenter argues AI models remain human-built algorithms while reflecting on recent AI-slop incidents in open-source
A reply posted on the oss-security mailing list reflects on recent AI-generated slop incidents, arguing that AI models are still human-developed algorithms running on human-built hardware. The post is personal commentary and contains no CVEs, advisories, or concrete incidents.
Re: AI slops from Eve
oss-security moderator Solar Designer says he may reject repetitive AI-generated postings after debate over AI slop submissions.
oss-security list moderator Solar Designer responded to criticism triggered by AI-generated 'slop' postings from an account known as Eve, saying that in his moderator role he may start rejecting repetitive AI-generated submissions. The brief thread reflects open-source security community concern about automated content quality on the mailing list.
Apple has a new way prove your iPhone photos aren’t AI slop
Apple launched Reference Image, cryptographically signing iPhone 18 Pro photos via Private Cloud Compute to prove image authenticity.
Announced at Apple's Surprise and Shine event, Apple Reference Image captures signed sensor data with the iPhone 18 Pro camera and uses Private Cloud Compute to create an unalterable 'digital negative' viewable in Photos. The reference image can be compared with edited versions to verify authenticity, and developer APIs enable third-party integration. Apple also said it will support the SynthID standard to identify AI-created or altered images.
Re: AI slops from Eve
David Wheeler's oss-security reply argues AI will make attacks far cheaper and more prolific, urging defenders to protect all IT systems, not just critical ones.
David A. Wheeler posted an opinion reply on the oss-security mailing list in a thread titled 'AI slops from Eve'. He agrees critical IT systems need protection but stresses that all systems have always required defense, since many who assumed they would not be attacked were successfully attacked. He predicts AI-enabled attacks will be painful for many over the next few years because AI greatly reduces the cost of attacks. He also notes AI simultaneously helps with finding and fixing issues.
Re: AI slops from Eve
Solar Designer finds little similarity between recent LLM-generated fake advisories on oss-security beyond missing Date headers.
A mailing-list thread discusses 'AI slops', LLM-generated fake security reports posted to oss-security. Solar Designer notes the suspicious messages share only trivial traits like a missing Date header and LLM use. He concludes there is no significant problem with any particular sender or model and no investigation is needed.
Re: AI slops from Eve
Jeroen Roovers links a header-less LLM-generated advisory to a similar fake llama.cpp GGUF parser advisory from May 2026.
In the 'AI slops from Eve' oss-security thread, Jeroen Roovers asks whether a current LLM-generated message without a Date header comes from the same source as a May 15, 2026 posting titled 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers'. Both fake advisories share the missing Date header trait. The exchange highlights growing LLM-generated noise on security mailing lists.