AI 正在生成虚假的 CVE(通用漏洞披露)——并且这些虚假信息正在进入真实的漏洞数据库

安全与信任 56 min ago3加入收藏

AI 正在生成虚假的 CVE(通用漏洞披露)——并且这些虚假信息正在进入真实的漏洞数据库
插图 : Léa Fontaine

一家美国公司确认,由人工智能“虚构”的SQLite漏洞条目正在通过初步审查,并进入实际的安全报告流程。这是一个此前无人设计的新攻击面。

简言之: AI工具正在编造出现实代码中并不存在的安全漏洞——而其中一些虚构的条目已进入安全团队用于决定修复内容的数据库。

事实

据ITmedia AI+报道,一家美国安全公司分析了针对SQLite的AI生成CVE条目,并确认在某些自动化流程中,虚构的漏洞通过了初步筛选并进入了真实的安全报告系统。这些条目描述的漏洞在SQLite的实际代码库中并不存在。CVE代表“通用漏洞披露”——这是全球安全工具、扫描器和补丁管理器依赖的漏洞索引。

我们的观点

这是AI“幻觉”在供应链层面的体现,其后果与聊天机器人编造内容的影响截然不同。NVD(国家漏洞数据库)早已积压严重——多年来一直难以处理合法的提交内容。虚假条目不仅浪费分析师时间:它们还会为自动扫描器生成误报,可能在优先级队列中挤占真实漏洞。任何未经人工验证直接采用CVE数据源的安全工作流程如今都面临结构性风险。解决方案并不简单——CVE报告本身就是半自动化的,要为AI来源添加标记,需要MITRE、NIST与数百家下游厂商的协调。

关注点

MITRE是否会更新提交政策,要求披露来源;以及各大安全平台是否会在其数据源中标记AI辅助生成的CVE条目。

本文由人工智能撰写,并经人工编辑审核。

我们的编辑部
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
这篇文章对您有帮助吗?

3 人赞了这篇文章

S
Sofia Adler安全与信任
🇨🇳 人工智能安全、模型可靠性、网络安全
分享:
评论 (3)

登录后即可参与讨论。

TravelTom 05 Aug 2026 · 13:13

Isn’t the real issue that vulnerability databases need better verification systems before AI gets involved, rather than blaming the AI itself?

FoodieChicago 05 Aug 2026 · 12:48

This is a serious problem. AI-generated vulnerabilities could dilute real threats over time, making it harder to prioritize actual risks effectively.

Alex_LDN 05 Aug 2026 · 12:46

That's worrying. If AI is creating fake vulnerabilities, it could waste a lot of teams' time chasing dead ends. How will we ever trust automated threat detection if the sources themselves are unreliable?

Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
主题
浏览
信息