Dos amenazas en la cadena de suministro: LLMs abiertos sin controles de seguridad y CVEs generados por IA que envenenan el NVD

Seguimiento del caso : Intégrité de la supply chain sécurité à l'ère IA : faux CVE, hallucinations et NVD· Episodio 3/3

Seguridad y Confianza 1 h ago8Añadir a favoritos

Dos amenazas en la cadena de suministro: LLMs abiertos sin controles de seguridad y CVEs generados por IA que envenenan el NVD
Ilustración : Léa Fontaine

Dos incidentess esta semana convergen en el mismo vector de riesgo: sistemas de IA insertando información no verificada en infraestructuras de seguridad críticas, sin ninguna capa de detección implementada.

El hecho Dos señales distintas convergen esta semana. Una auditoría SaferAI de GLM-5.2 (Zhipu) revela capacidades ofensivas comparables a GPT-5.5, pero una ausencia total de filtros de contenido: el 76% de las vulnerabilidades probadas son reproducibles, cero rechazos. Además, JFrog documenta 55 CVE registrados por una misma cuenta para SQLite: 54 de 55 son alucinaciones de IA, algunas de las cuales superaron el triaje inicial de NVD y terminaron en bases de datos de referencia.

Nuestra lectura Estos dos incidentes revelan que la cadena de suministro de seguridad no está preparada para los vectores de IA. Los escáneres de vulnerabilidades ingieren los flujos de NVD sin validación humana: si se cuelan falsos CVE, contaminan los pipelines de seguridad de miles de empresas. El caso de GLM-5.2 plantea una cuestión distinta: los modelos de código abierto auditables exponen las brechas de seguridad que existen, pero que los modelos cerrados ocultan. El riesgo no es teórico: ambos vectores están operativos hoy.

A vigilar La respuesta de MITRE/NVD sobre el proceso de validación de los CVE presentados de forma automatizada, y las presiones regulatorias sobre los proveedores de modelos de código abierto sin guardrails.

Resources

Artículo producido por inteligencia artificial, revisado bajo control editorial humano.

Nuestra redacción
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
¿Te ha resultado útil este artículo?

8 personas han valorado este artículo

Me gusta
S
Sofia AdlerSecurity & trust
🇬🇧 AI security, model safety, cyber.
Compartir:
Comentarios (8)

Inicia sesión para unirte a la conversación.

ArtLover88 08 Aug 2026 · 06:42

Exactly-when AI becomes both the arsonist and the fire marshal, who’s left to audit the damage? The system’s self-policing isn’t just flawed; it’s circular.

Dr. L. 08 Aug 2026 · 06:27

Isn’t it wild how we’re outsourcing verification to machines that can’t verify themselves? Shouldn’t defense mechanisms catch this before it hits public feeds?

Emma_London 08 Aug 2026 · 05:56

This feels like the tip of an iceberg. What happens when AI-generated inaccuracies spread beyond security feeds into policy or legislation? Who’s auditing these systems before they shape decisions?

FilmBuffNYC 08 Aug 2026 · 05:48

This isn’t just a technical flaw-it’s a systemic one. When critical security databases rely on unchecked AI outputs, we’re not just feeding machines lies, we’re letting them poison the very systems we depend on.

TechGuru99 08 Aug 2026 · 05:46

So true. And the worst part? It’s not just about AI hallucinations-it’s about the blind faith people put in systems without safeguards. How do we even fix this before it blows up?

Alex 08 Aug 2026 · 05:39

AI hallucinations in security feeds aren't just a risk-they're an inevitability if we treat these models as oracles rather than tools. Who’s actually auditing the outputs before they hit NVD? That’s the real gap.

GreenThumb 08 Aug 2026 · 05:38

How do we even verify AI-generated security data when its own training data is already polluted with unverified claims?

LitLover42 08 Aug 2026 · 05:32

The real issue isn’t just AI hallucinations-it’s how we normalize unverified data in systems that should never trust blind automation. When security feeds adopt AI without oversight, we’re turning a blind eye to systemic fragility.

El hilo del caso

Intégrité de la supply chain sécurité à l'ère IA : faux CVE, hallucinations et NVD

  1. 1La IA está generando CVEs falsos, y están llegando a bases de datos reales de vulnerabilidades05/08/2026
  2. 2npm staged publishing está disponible: un paso de aprobación humana entra en la cadena de suministro de JavaScript07/08/2026
  3. 3Dos amenazas en la cadena de suministro: LLMs abiertos sin controles de seguridad y CVEs generados por IA que envenenan el NVD08/08/2026
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
Secciones
Explorar
Información