AI slops from Eve: LLM-generated fake advisories posted to oss-security
On 2026-09-13, an oss-security thread ("AI slops from Eve") discussed LLM-generated fake advisories; Jeroen Roovers linked one to a fake llama.cpp GGUF parser advisory from May 15, 2026, while Solar Designer found little similarity beyond missing Date headers…
The oss-security mailing list thread 'AI slops from Eve' (messages dated 2026-09-13T14:51:07Z and 2026-09-13T15:08:53Z) concerns 'AI slops' — LLM-generated fake security reports posted to the list. Jeroen Roovers asked whether a current LLM-generated message lacking a Date header comes from the same source as a May 15, 2026 posting titled 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers', noting both fake advisories share the missing Date header trait. Solar Designer countered that the suspicious messages share only trivial traits, namely a missing Date header and LLM use, and concluded there is no significant problem with any particular sender or model and no investigation is needed. The sources disagree on linkage: Roovers connects the postings, while Solar Designer sees little similarity beyond those trivial traits. The thread highlights growing LLM-generated noise on security mailing lists; the referenced advisories are fake, and no CVE ids or real vulnerable software versions are given in the reports.
- Thread 'AI slops from Eve' on oss-security; messages timestamped 2026-09-13T14:51:07.000Z (Jeroen Roovers) and 2026-09-13T15:08:53.000Z (Solar Designer).
- 'AI slops' are LLM-generated fake security advisories posted to the oss-security mailing list.
- Jeroen Roovers links a header-less LLM-generated advisory to the May 15, 2026 posting 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers'.
- The two fake advisories share the trait of a missing Date header.
- Solar Designer notes the suspicious messages share only trivial traits (missing Date header, LLM use) and finds no significant problem with any particular sender or model; he says no investigation is needed.
- Sources disagree on whether the current message and the May 15, 2026 llama.cpp advisory come from the same source: Roovers links them, Solar Designer sees little similarity beyond trivial traits.
- The llama.cpp GGUF parser advisory referenced is fake (LLM-generated); no CVE ids, affected versions, or real vulnerability counts are stated in the reports.
Coverage timelineoldest first · each row is one article
- · 13d agoRe: AI slops from Eve
oss-security· 6
Jeroen Roovers links a header-less LLM-generated advisory to a similar fake llama.cpp GGUF parser advisory from May 2026.
- · 13d agoRe: AI slops from Eve
oss-security· 6
Solar Designer finds little similarity between recent LLM-generated fake advisories on oss-security beyond missing Date headers.