ZeroHour
Story · 1 source · 11 articlesfirst updated ()1

LLM-generated 'slop' postings from 'Eve' spark moderation debate on oss-security mailing list

infoOtherimportance 12
What's new: 2026-09-10: Eli Schwartz publicly criticizes Eve's AI-generated posts and calls for de-humanizing bot submitters. 2026-09-11: Moderator Solar Designer says he may start rejecting repetitive AI-generated postings and clarifies moderation is content-based, not domain-based, pushing back against Joe Krause's advice to treat cock.li mail as spam. 2026-09-12: Discussion widens to AI threat trends,…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Between 2026-09-10 and 2026-09-13, the oss-security mailing list debated AI-generated 'slop' posts submitted under the name 'Eve', including LLM-produced fake advisories. Moderator Solar Designer said he may reject repetitive AI-generated submissions, argued…

A thread titled 'AI slops from Eve' ran on the oss-security mailing list from 2026-09-10 through 2026-09-13, concerning LLM-generated postings, including fake security advisories, submitted under the name 'Eve'. Eli Schwartz called the submissions incoherent or probably wrong and urged the community to stop anthropomorphizing bots or triaging their reports as if they were human correspondence. Moderator Solar Designer said he may start rejecting repetitive AI-generated submissions and clarified that the list moderates primarily by content rather than sender domain, noting no domain produces enough unwanted traffic to warrant pre-filtering — a counterpoint to Joe Krause, who described the mail provider cock.li as hosting many script kiddies and advised treating almost any email from that domain as spam (the sources disagree on this point). Solar Designer referenced a mail hosting provider claiming roughly 1.4 million users in that exchange. Jeroen Roovers linked a current header-less LLM-generated advisory to a May 15, 2026 posting titled 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers', both sharing a missing Date header; Solar Designer concluded the suspicious messages share only trivial traits (missing Date header, LLM use), that no particular sender or model is a significant problem, and that no investigation is needed. Broader commentary included David A. Wheeler's prediction that AI will greatly reduce the cost of attacks and thus greatly proliferate them (while also aiding finding and fixing issues), Collin Funk's criticism of AI labs offering short free compute trials to open-source projects to create paid dependency, and an unnamed poster's argument that AI models remain human-built algorithms on human-built hardware. No CVE, vulnerability, or exploitation details were involved; the posts are commentary plus references to fake advisories.

  • The 'AI slops from Eve' thread on oss-security spans posts dated 2026-09-10T16:32Z to 2026-09-13T15:08Z.
  • The postings at issue are LLM-generated, including fake security advisories, submitted under the name 'Eve'.
  • Eli Schwartz (2026-09-10) said the AI-generated submissions are incoherent or probably wrong and urged volunteers to stop anthropomorphizing bots.
  • Moderator Solar Designer (2026-09-11) said he may start rejecting repetitive AI-generated submissions on oss-security.
  • Solar Designer (2026-09-11) said moderation is primarily by content rather than sender domain, and that no domain produces enough unwanted traffic to warrant pre-filtering; he referenced a mail hosting provider claiming roughly 1.4 million…
  • Joe Krause (2026-09-11) described cock.li as a mail host housing many script kiddies and advised treating almost any email from that domain as spam; this conflicts with Solar Designer's content-based moderation stance.
  • Jeroen Roovers (2026-09-13) linked a current header-less LLM-generated advisory to a May 15, 2026 posting titled 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers'; both fake advisories share a missing Date…
  • Solar Designer (2026-09-13) found little similarity among the recent fake advisories beyond missing Date headers and LLM use, concluding no particular sender or model poses a significant problem and no investigation is needed.

Coverage timeline

  1. · 6d ago
    oss-security· 4
    Re: AI slops from Eve

    Eli Schwartz on the oss-security list criticizes AI-generated 'slop' posts from 'Eve', urging the community to stop anthropomorphizing bots.

  2. · 6d ago
    oss-security· 2
    Re: AI slops from Eve

    oss-security subscriber Jeffrey Walton asks posters to refer to computer algorithms as 'it' rather than personifying them as 'he' or 'she'.

  3. · 6d ago
    oss-security· 5
    Re: AI slops from Eve

    oss-security thread 'AI slops from Eve' continues with English grammar corrections rather than security content.

  4. · 5d ago
    oss-security· 12
    Re: AI slops from Eve

    oss-security commenter argues AI models remain human-built algorithms while reflecting on recent AI-slop incidents in open-source

  5. · 5d ago
    oss-security· 12
    Re: AI slops from Eve

    oss-security moderator Solar Designer says he may reject repetitive AI-generated postings after debate over AI slop submissions.

  6. · 5d ago
    oss-security· 5
    Re: AI slops from Eve

    oss-security contributor Joe Krause warns that emails from mail provider cock.li, which he says hosts many script kiddies, should be treated as spam.

  7. · 5d ago
    oss-security· 5
    Re: AI slops from Eve

    oss-security maintainer Solar Designer explains the list moderates by content rather than sender domain amid ongoing AI-generated spam postings.

  8. · 4d ago
    oss-security· 12
    Re: AI slops from Eve

    David Wheeler's oss-security reply argues AI will make attacks far cheaper and more prolific, urging defenders to protect all IT systems, not just critical ones.

  9. · 4d ago
    oss-security· 2
    Re: AI slops from Eve

    Mailing-list reply criticizing AI labs for offering short free compute trials to free software projects instead of real support.

  10. · 3d ago
    oss-security· 6
    Re: AI slops from Eve

    Jeroen Roovers links a header-less LLM-generated advisory to a similar fake llama.cpp GGUF parser advisory from May 2026.

  11. · 3d ago
    oss-security· 6
    Re: AI slops from Eve

    Solar Designer finds little similarity between recent LLM-generated fake advisories on oss-security beyond missing Date headers.