{
  "id": 13103170,
  "title": "In open source cybersecurity, AI is kind of a problem — but it can also be a solution",
  "url": "https://urgent.news/2026/10/09/in-open-source-cybersecurity-ai-is-kind-of-a-problem-but-it-can-also",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-09T11:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/in-open-source-cybersecurity-ai-is-kind-of-a-problem-but-it-can-also-be-a-solution"
  },
  "original_language": "en",
  "account": "In recent years, a growing number of vulnerability disclosures have overwhelmed the cybersecurity industry, and while AI is a significant contributor to this problem, it can also provide essential solutions. IBM's Chief Client Innovation Officer for Enterprise Security, Jamie Thomas, warned at the Linux Foundation Open Source Summit that there's a \"tsunami in vulnerability disclosures,\" with an expected 66,000 unique entries in 2026, a fourfold increase from seven years ago. The cybersecurity industry needs to find a way to keep up with this pace, especially as expectations on developers and security professionals keep growing. AI can help in this regard, as it can identify vulnerabilities and improve software security. However, it can also create inaccurate, duplicated, and unactionable vulnerability reports, making the task of open-source maintainers even more challenging. Large companies may have dedicated security teams, but many open-source projects are maintained by small groups of developers, sometimes even a single individual. The developers of curl, a popular open-source command-line tool, recently terminated their HackerOne bug bounty program due to the influx of poorly researched and fake reports, some of which were AI-generated. Even Google had to temporarily suspend its Open Source Software Vulnerability Rewards Program due to an increase in invalid and irrelevant reports, many of which were AI-generated. Linus Torvalds, the creator of Linux, also expressed concern over the issue, stating that AI-powered bug hunters have made the Linux security mailing list almost entirely unmanageable. Some reports found that the majority of AI-generated remediation suggestions caused more problems than they solved. To tackle this issue, IBM suggests that the security community should not abandon AI-powered vulnerability discovery but use the same technology to help maintainers handle the growing workload. This involves strengthening supply chain security and reducing the burden on maintainers through AI-powered tools that filter out duplicate and bogus reports, assess the severity of different bugs, and identify issues that need urgent attention.",
  "summary": "Approximately 66,000 unique entries are expected to emerge in 2026 , many boosted or even created by AI.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}