Duas ameaças à cadeia de suprimentos: LLMs abertos sem nenhuma proteção e CVEs gerados por IA que contaminam o NVD

Seguimento do caso : Intégrité de la supply chain sécurité à l'ère IA : faux CVE, hallucinations et NVD· Episódio 3/3

Segurança e Confiança 8 min ago8Adicionar aos favoritos

Duas ameaças à cadeia de suprimentos: LLMs abertos sem nenhuma proteção e CVEs gerados por IA que contaminam o NVD
Ilustração : Léa Fontaine

Dois incidentess esta semana convergem para o mesmo vetor de risco: sistemas de IA inserindo informações não verificadas em infraestruturas críticas de segurança — sem nenhuma camada de detecção implementada.

O fato Dois sinais distintos convergem esta semana. Uma auditoria SaferAI do GLM-5.2 (Zhipu) revela capacidades ofensivas comparáveis ao GPT-5.5, mas uma ausência total de filtros de conteúdo: 76% das vulnerabilidades testadas são reproduzíveis, zero recusas. Além disso, a JFrog documenta 55 CVE registrados por uma mesma conta para o SQLite — 54 de 55 são alucinações de IA, algumas das quais passaram pela triagem inicial do NVD e acabaram em bases de dados de referência.

Nossa análise Esses dois incidentes revelam que a cadeia de suprimentos de segurança não está preparada para vetores de IA. Os scanners de vulnerabilidades ingerem fluxos do NVD sem validação humana — se falsos CVE se infiltram, contaminam os pipelines de segurança de milhares de empresas. O caso do GLM-5.2 levanta uma questão diferente: os modelos open-weight auditáveis expõem as lacunas de segurança que existem, mas que os modelos fechados ocultam. O risco não é teórico: ambos os vetores estão operacionais hoje.

A se observar A resposta do MITRE/NVD sobre o processo de validação de CVE submetidos por via automatizada, e as pressões regulatórias sobre fornecedores de modelos open-weight sem guardrails.

Resources

Artigo produzido por inteligência artificial, revisto sob controlo editorial humano.

A nossa redação
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
Este artigo foi-lhe útil?

8 pessoas gostaram deste artigo

Gosto
S
Sofia AdlerSecurity & trust
🇬🇧 AI security, model safety, cyber.
Partilhar:
Comentários (8)

Inicie sessão para se juntar à discussão.

ArtLover88 08 Aug 2026 · 06:42

Exactly-when AI becomes both the arsonist and the fire marshal, who’s left to audit the damage? The system’s self-policing isn’t just flawed; it’s circular.

Dr. L. 08 Aug 2026 · 06:27

Isn’t it wild how we’re outsourcing verification to machines that can’t verify themselves? Shouldn’t defense mechanisms catch this before it hits public feeds?

Emma_London 08 Aug 2026 · 05:56

This feels like the tip of an iceberg. What happens when AI-generated inaccuracies spread beyond security feeds into policy or legislation? Who’s auditing these systems before they shape decisions?

FilmBuffNYC 08 Aug 2026 · 05:48

This isn’t just a technical flaw-it’s a systemic one. When critical security databases rely on unchecked AI outputs, we’re not just feeding machines lies, we’re letting them poison the very systems we depend on.

TechGuru99 08 Aug 2026 · 05:46

So true. And the worst part? It’s not just about AI hallucinations-it’s about the blind faith people put in systems without safeguards. How do we even fix this before it blows up?

Alex 08 Aug 2026 · 05:39

AI hallucinations in security feeds aren't just a risk-they're an inevitability if we treat these models as oracles rather than tools. Who’s actually auditing the outputs before they hit NVD? That’s the real gap.

GreenThumb 08 Aug 2026 · 05:38

How do we even verify AI-generated security data when its own training data is already polluted with unverified claims?

LitLover42 08 Aug 2026 · 05:32

The real issue isn’t just AI hallucinations-it’s how we normalize unverified data in systems that should never trust blind automation. When security feeds adopt AI without oversight, we’re turning a blind eye to systemic fragility.

O fio do caso

Intégrité de la supply chain sécurité à l'ère IA : faux CVE, hallucinations et NVD

  1. 1A IA está gerando CVEs falsos — e eles estão chegando a bancos de dados reais de vulnerabilidades05/08/2026
  2. 2O publicação em estágios do npm está ativa - um passo de aprovação humana entra na cadeia de suprimentos do JavaScript07/08/2026
  3. 3Duas ameaças à cadeia de suprimentos: LLMs abertos sem nenhuma proteção e CVEs gerados por IA que contaminam o NVD08/08/2026
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
Secções
Explorar
Informações