ZeroHour
Story · 1 source · 12 articlesfirst updated ()3· 1 read

AI slops from Eve: oss-security debate over LLM-generated advisories ends with moderator finding no common source

infoIndustryimportance 18
What's new: Since the previous summary (September 12, 2026), Jeroen Roovers linked the header-less LLM-generated messages to a similar fake advisory from May 15, 2026 about llama.cpp GGUF format parsers, and Solar Designer responded that the messages share only trivial traits such as missing Date headers and LLM use, concluding there is no significant problem with any particular sender or model and that no…
Merged summary · glm-5.3 · rewritten as coverage arrives

Three AI-generated posts from 'Eve', an 'automated security researcher', approved on oss-security sparked a multi-day debate (Sept 10-13, 2026) over AI slop on vulnerability mailing lists, ending with moderator Solar Designer concluding the fake advisories…

On September 9, 2026, three posts submitted by 'Eve', described as an 'automated security researcher', arrived on the oss-security list server lacking Date headers; moderator Solar Designer approved them despite uncertainty about their value, suggesting they may have historical significance as early examples of AI-generated security reports at the dawn of AI security research. Eli Schwartz replied that the submissions were incoherent or probably wrong, urged the community to stop anthropomorphizing the program, mocked the sender's 'colorfully professional' joke email domain, and argued that volunteers triaging bot reports like human correspondence is counterproductive. Subsequent replies debated grammar ('which' versus 'it') and argued AI models remain human-developed algorithms running on human-built hardware. Responding to criticism, Solar Designer said he may start rejecting repetitive AI-generated postings in his moderator role. Joe Krause then warned that mail provider cock.li houses many script kiddies and advised treating almost any email from that domain as spam; Solar Designer replied that moderation is primarily by content rather than sender domain, that no domain produces enough unwanted traffic to warrant pre-filtering, referencing a mail hosting provider claiming roughly 1.4 million users. David A. Wheeler predicted AI-enabled attacks will be painful for many over the next few years because AI greatly reduces the cost of attacks, stressed that all systems (not just critical ones) have always required defense since many who assumed they would not be attacked were successfully attacked, and noted AI simultaneously helps with finding and fixing vulnerabilities. On September 13, Jeroen Roovers asked whether a current LLM-generated message without a Date header came from the same source as a May 15, 2026 posting titled 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers', noting both fake advisories shared the missing-Date-header trait. Solar Designer closed the thread by finding the suspicious messages share only trivial traits such as a missing Date header and LLM use, concluding there is no significant problem with any particular sender or model and no investigation is needed. No CVE identifiers, software versions, or exploitation details appear in any report. Sources disagree on the posts' value: the moderator saw possible historical significance as early AI-written security reports, while Schwartz judged them…

  • Three AI-generated posts by 'Eve', an 'automated security researcher', were approved by moderator Solar Designer; they lacked Date headers and arrived on the list server on September 9, 2026.
  • Eli Schwartz called the submissions incoherent or probably wrong, urged the community to stop anthropomorphizing the program, mocked the sender's joke email domain, and said volunteers triaging bot reports is counterproductive.
  • Solar Designer said he may start rejecting repetitive AI-generated postings on oss-security.
  • Joe Krause described cock.li as a mail host housing many script kiddies and advised treating emails from that domain as spam; Solar Designer said moderation is by content, not sender domain, noting no domain produces enough unwanted…
  • David A. Wheeler predicted AI-enabled attacks will proliferate over the next few years because AI greatly reduces attack costs, all systems have always needed defense, and AI also aids finding and fixing vulnerabilities.
  • Jeroen Roovers asked whether the header-less LLM-generated messages came from the same source as a May 15, 2026 fake advisory titled 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers'.
  • Solar Designer concluded the suspicious messages share only trivial traits (missing Date header, LLM use), with no significant problem attributable to any particular sender or model and no investigation needed.
  • No CVE identifiers, versions, exploit code, or exploitation details appear in any report; the thread is meta-commentary, not a vulnerability disclosure.

Coverage timeline

  1. · 5d ago
    oss-security· 18
    AI slops from Eve

    oss-security moderator Solar Designer approved three AI-generated vulnerability reports from automated security researcher Eve, sparking debate over AI slop on the list.

  2. · 5d ago
    oss-security· 4
    Re: AI slops from Eve

    Eli Schwartz on the oss-security list criticizes AI-generated 'slop' posts from 'Eve', urging the community to stop anthropomorphizing bots.

  3. · 5d ago
    oss-security· 2
    Re: AI slops from Eve

    oss-security subscriber Jeffrey Walton asks posters to refer to computer algorithms as 'it' rather than personifying them as 'he' or 'she'.

  4. · 4d ago
    oss-security· 5
    Re: AI slops from Eve

    oss-security thread 'AI slops from Eve' continues with English grammar corrections rather than security content.

  5. · 4d ago
    oss-security· 12
    Re: AI slops from Eve

    oss-security commenter argues AI models remain human-built algorithms while reflecting on recent AI-slop incidents in open-source

  6. · 4d ago
    oss-security· 12
    Re: AI slops from Eve

    oss-security moderator Solar Designer says he may reject repetitive AI-generated postings after debate over AI slop submissions.

  7. · 4d ago
    oss-security· 5
    Re: AI slops from Eve

    oss-security contributor Joe Krause warns that emails from mail provider cock.li, which he says hosts many script kiddies, should be treated as spam.

  8. · 4d ago
    oss-security· 5
    Re: AI slops from Eve

    oss-security maintainer Solar Designer explains the list moderates by content rather than sender domain amid ongoing AI-generated spam postings.

  9. · 3d ago
    oss-security· 12
    Re: AI slops from Eve

    David Wheeler's oss-security reply argues AI will make attacks far cheaper and more prolific, urging defenders to protect all IT systems, not just critical ones.

  10. · 2d ago
    oss-security· 2
    Re: AI slops from Eve

    Mailing-list reply criticizing AI labs for offering short free compute trials to free software projects instead of real support.

  11. · 2d ago
    oss-security· 6
    Re: AI slops from Eve

    Jeroen Roovers links a header-less LLM-generated advisory to a similar fake llama.cpp GGUF parser advisory from May 2026.

  12. · 2d ago
    oss-security· 6
    Re: AI slops from Eve

    Solar Designer finds little similarity between recent LLM-generated fake advisories on oss-security beyond missing Date headers.