Urgent.News

What's breaking now, across thousands of outlets.

AI

In open source cybersecurity, AI is kind of a problem — but it can also be a solution

Approximately 66,000 unique entries are expected to emerge in 2026 , many boosted or even created by AI.

In open source cybersecurity, AI is kind of a problem — but it can also be a solution

In recent years, a growing number of vulnerability disclosures have overwhelmed the cybersecurity industry, and while AI is a significant contributor to this problem, it can also provide essential solutions. IBM's Chief Client Innovation Officer for Enterprise Security, Jamie Thomas, warned at the Linux Foundation Open Source Summit that there's a "tsunami in vulnerability disclosures," with an expected 66,000 unique entries in 2026, a fourfold increase from seven years ago.

The cybersecurity industry needs to find a way to keep up with this pace, especially as expectations on developers and security professionals keep growing. AI can help in this regard, as it can identify vulnerabilities and improve software security. However, it can also create inaccurate, duplicated, and unactionable vulnerability reports, making the task of open-source maintainers even more challenging.

Large companies may have dedicated security teams, but many open-source projects are maintained by small groups of developers, sometimes even a single individual. The developers of curl, a popular open-source command-line tool, recently terminated their HackerOne bug bounty program due to the influx of poorly researched and fake reports, some of which were AI-generated.

Even Google had to temporarily suspend its Open Source Software Vulnerability Rewards Program due to an increase in invalid and irrelevant reports, many of which were AI-generated. Linus Torvalds, the creator of Linux, also expressed concern over the issue, stating that AI-powered bug hunters have made the Linux security mailing list almost entirely unmanageable.

Some reports found that the majority of AI-generated remediation suggestions caused more problems than they solved. To tackle this issue, IBM suggests that the security community should not abandon AI-powered vulnerability discovery but use the same technology to help maintainers handle the growing workload. This involves strengthening supply chain security and reducing the burden on maintainers through AI-powered tools that filter out duplicate and bogus reports, assess the severity of different bugs, and identify issues that need urgent attention.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in AI

Claude Opus 5.5 Effort Levels Tested: Low to Max

I'm a solo developer in Korea who builds games with AI. Claude Opus 5.5 has five effort levels, so I ran the same prompt at every one of them and measured it.

  • Claude Opus 5.5 offers five effort levels, from low to max
  • Low effort generates simple games in 32 seconds for $0.48
  • Max effort creates advanced games in 22 minutes 22 seconds for $5.25

More from Friday 9 October →