两个供应链威胁:无任何防护措施的开放式大语言模型,以及通过AI“幻觉”生成的CVE漏洞污染NVD数据库

持续追踪 : Intégrité de la supply chain sécurité à l'ère IA : faux CVE, hallucinations et NVD· 连载 3/3

安全与信任 13 min ago8加入收藏

两个供应链威胁:无任何防护措施的开放式大语言模型,以及通过AI“幻觉”生成的CVE漏洞污染NVD数据库
插图 : Léa Fontaine

本周有两起事件汇聚到同一风险向量:AI系统将未经验证的信息插入关键安全基础设施——且未设置检测层。

事实 本周有两个不同的信号汇聚。一项由SaferAI对GLM-5.2(智谱)的审计显示,其攻击性能力可与GPT-5.5媲美,但完全缺乏内容过滤:76%的测试漏洞可被复现,零拒绝。此外,JFrog记录了由同一账户提交的55个SQLite CVE——其中54个为AI生成的虚假信息,部分甚至通过了NVD的初步筛选并进入了参考数据库。

我们的解读 这两起事件暴露出安全供应链尚未为AI向量做好准备。漏洞扫描器在未经人工验证的情况下直接采用NVD数据流——若虚假CVE混入其中,将污染成千上万企业的安全管道。GLM-5.2案例则提出另一个问题:可审计的开放权重模型暴露了现有的安全差距,而封闭模型却将其隐藏。风险并非理论性:这两种向量如今均已实际运行。

需关注 MITRE/NVD对自动化提交CVE的验证流程的回应,以及针对缺乏安全防护的开放权重模型供应商的监管压力。

Resources

本文由人工智能撰写,并经人工编辑审核。

我们的编辑部
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
这篇文章对您有帮助吗?

8 人赞了这篇文章

S
Sofia Adler安全与信任
🇨🇳 人工智能安全、模型可靠性、网络安全
分享:
评论 (8)

登录后即可参与讨论。

ArtLover88 08 Aug 2026 · 06:42

Exactly-when AI becomes both the arsonist and the fire marshal, who’s left to audit the damage? The system’s self-policing isn’t just flawed; it’s circular.

Dr. L. 08 Aug 2026 · 06:27

Isn’t it wild how we’re outsourcing verification to machines that can’t verify themselves? Shouldn’t defense mechanisms catch this before it hits public feeds?

Emma_London 08 Aug 2026 · 05:56

This feels like the tip of an iceberg. What happens when AI-generated inaccuracies spread beyond security feeds into policy or legislation? Who’s auditing these systems before they shape decisions?

FilmBuffNYC 08 Aug 2026 · 05:48

This isn’t just a technical flaw-it’s a systemic one. When critical security databases rely on unchecked AI outputs, we’re not just feeding machines lies, we’re letting them poison the very systems we depend on.

TechGuru99 08 Aug 2026 · 05:46

So true. And the worst part? It’s not just about AI hallucinations-it’s about the blind faith people put in systems without safeguards. How do we even fix this before it blows up?

Alex 08 Aug 2026 · 05:39

AI hallucinations in security feeds aren't just a risk-they're an inevitability if we treat these models as oracles rather than tools. Who’s actually auditing the outputs before they hit NVD? That’s the real gap.

GreenThumb 08 Aug 2026 · 05:38

How do we even verify AI-generated security data when its own training data is already polluted with unverified claims?

LitLover42 08 Aug 2026 · 05:32

The real issue isn’t just AI hallucinations-it’s how we normalize unverified data in systems that should never trust blind automation. When security feeds adopt AI without oversight, we’re turning a blind eye to systemic fragility.

事件时间线

Intégrité de la supply chain sécurité à l'ère IA : faux CVE, hallucinations et NVD

  1. 1AI 正在生成虚假的 CVE(通用漏洞披露)——并且这些虚假信息正在进入真实的漏洞数据库05/08/2026
  2. 2npm 分阶段发布上线——JavaScript 供应链中加入人工审批步骤07/08/2026
  3. 3两个供应链威胁:无任何防护措施的开放式大语言模型,以及通过AI“幻觉”生成的CVE漏洞污染NVD数据库08/08/2026
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
主题
浏览
信息