<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[The AI slop security reporting is basically extinct.]]></title><description><![CDATA[<p>The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.</p>]]></description><link>https://board.circlewithadot.net/topic/af010520-8e50-442e-9787-d8678e22b157/the-ai-slop-security-reporting-is-basically-extinct.</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 22:57:51 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/af010520-8e50-442e-9787-d8678e22b157.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 15 Apr 2026 06:44:23 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 15:43:31 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> Seems like all you need to do is take away the incentive to get rid of the low effort reports. </p><p>Sad they had to ruin it for real reporters now as they don’t get their (deserved) bounty anymore in exchange for the good work they’re doing.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/Stephanie/statuses/116409487274410762</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/Stephanie/statuses/116409487274410762</guid><dc:creator><![CDATA[stephanie@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 15:43:31 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 14:14:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> Unfortunately that hasn't made it to Flask yet, we still get a bunch of AI slop. About 50 reports so far this year, none helpful. Typically we get &lt; 10 per year, some helpful.</p>]]></description><link>https://board.circlewithadot.net/post/https://mas.to/users/davidism/statuses/116409137785918206</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mas.to/users/davidism/statuses/116409137785918206</guid><dc:creator><![CDATA[davidism@mas.to]]></dc:creator><pubDate>Wed, 15 Apr 2026 14:14:38 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 13:28:59 GMT]]></title><description><![CDATA[<span><a href="/user/mjd%40mathstodon.xyz">@mjd@mathstodon.xyz</a></span> <span><a href="/user/pozorvlak%40mathstodon.xyz">@pozorvlak@mathstodon.xyz</a></span> I mean, it’s terrible for the environment, has loads of ethical and moral concerns, and the companies are completely unsustainable. It’s pretty easy to hate<br />]]></description><link>https://board.circlewithadot.net/post/https://snac.benbuhse.com/ben/p/1776259739.343984</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://snac.benbuhse.com/ben/p/1776259739.343984</guid><dc:creator><![CDATA[ben@snac.benbuhse.com]]></dc:creator><pubDate>Wed, 15 Apr 2026 13:28:59 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 12:37:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social" rel="nofollow noopener">@<span>bagder</span></a></span> I wonder how much of that is because you eliminated the bounty</p>]]></description><link>https://board.circlewithadot.net/post/https://social.treehouse.systems/users/nicolas17/statuses/116408755961709456</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.treehouse.systems/users/nicolas17/statuses/116408755961709456</guid><dc:creator><![CDATA[nicolas17@social.treehouse.systems]]></dc:creator><pubDate>Wed, 15 Apr 2026 12:37:32 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 11:09:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/utopiah%40mastodon.pirateparty.be">@<span>utopiah</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> there's no irony at all, it's at minimum a marketing strategy.</p>]]></description><link>https://board.circlewithadot.net/post/https://en.osm.town/users/mdione/statuses/116408411652201220</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://en.osm.town/users/mdione/statuses/116408411652201220</guid><dc:creator><![CDATA[mdione@en.osm.town]]></dc:creator><pubDate>Wed, 15 Apr 2026 11:09:58 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 10:34:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> you're lucky. I got 30+ yesterday. 1 was kind of credible. The others were effectively documented behaviors of projects.<br />There's still little to no consequences for wasting time - I've been thinking about the "name and shame" approach you have, maybe that helps change the behavior?</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/miketheman/statuses/116408272167750043</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/miketheman/statuses/116408272167750043</guid><dc:creator><![CDATA[miketheman@hachyderm.io]]></dc:creator><pubDate>Wed, 15 Apr 2026 10:34:30 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 10:23:44 GMT]]></title><description><![CDATA[Yes, it would be nice if we stopped building hell so people can roast a few marshmallows. Marshmallows are nice, but not that nice.<br /><br />CC: <span><a href="/user/pozorvlak%40mathstodon.xyz">@pozorvlak@mathstodon.xyz</a></span><br />]]></description><link>https://board.circlewithadot.net/post/https://hj.9fs.net/ori/p/1776248624.925397</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hj.9fs.net/ori/p/1776248624.925397</guid><dc:creator><![CDATA[ori@hj.9fs.net]]></dc:creator><pubDate>Wed, 15 Apr 2026 10:23:44 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 10:11:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/mjd%40mathstodon.xyz">@<span>mjd</span></a></span> ah, good point. Reliably bad reports waste a small amount of time, but more than zero. The worst case is reports that are only sometimes good, because then you have to read them all carefully.</p>]]></description><link>https://board.circlewithadot.net/post/https://mathstodon.xyz/users/pozorvlak/statuses/116408183607751925</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mathstodon.xyz/users/pozorvlak/statuses/116408183607751925</guid><dc:creator><![CDATA[pozorvlak@mathstodon.xyz]]></dc:creator><pubDate>Wed, 15 Apr 2026 10:11:58 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 09:56:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/pozorvlak%40mathstodon.xyz">@<span>pozorvlak</span></a></span> If that were the reason, wouldn't they want the reports to be as good as possible, and be glad if the reports were all worth reading?  But this person says they are disappointed!</p>]]></description><link>https://board.circlewithadot.net/post/https://mathstodon.xyz/users/mjd/statuses/116408124472039512</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mathstodon.xyz/users/mjd/statuses/116408124472039512</guid><dc:creator><![CDATA[mjd@mathstodon.xyz]]></dc:creator><pubDate>Wed, 15 Apr 2026 09:56:56 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 09:53:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/mjd%40mathstodon.xyz">@<span>mjd</span></a></span> I think so. But also, if all AI-generated bug reports are useless, you can stop reading as soon as you've decided a bug report came from an AI.</p>]]></description><link>https://board.circlewithadot.net/post/https://mathstodon.xyz/users/pozorvlak/statuses/116408111857829499</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mathstodon.xyz/users/pozorvlak/statuses/116408111857829499</guid><dc:creator><![CDATA[pozorvlak@mathstodon.xyz]]></dc:creator><pubDate>Wed, 15 Apr 2026 09:53:44 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 09:50:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> sure, ironically enough there is no "I" in AI.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.pirateparty.be/users/utopiah/statuses/116408097541889465</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.pirateparty.be/users/utopiah/statuses/116408097541889465</guid><dc:creator><![CDATA[utopiah@mastodon.pirateparty.be]]></dc:creator><pubDate>Wed, 15 Apr 2026 09:50:05 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 09:47:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/pozorvlak%40mathstodon.xyz">@<span>pozorvlak</span></a></span> Now I think a more reasonable interpretation is: they are concerned about copyright violations, environmental damage, etc., and are dismayed that people like me use AI anyway. The fact of its getting better doesn't fix the other problems, and just means that there are fewer arguments against using it.</p><p>(“This is terrible” vs. “This is terrible, maybe when people realise that it doesn't work, they will stop.”)</p>]]></description><link>https://board.circlewithadot.net/post/https://mathstodon.xyz/users/mjd/statuses/116408085636232775</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mathstodon.xyz/users/mjd/statuses/116408085636232775</guid><dc:creator><![CDATA[mjd@mathstodon.xyz]]></dc:creator><pubDate>Wed, 15 Apr 2026 09:47:03 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 09:39:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/pozorvlak%40mathstodon.xyz">@<span>pozorvlak</span></a></span> To me, the most interesting part of that thread was this post. </p><p>This person considers AI their enemy. But not because it is wasting Stenberg's time. They wanted it to continue to waste Stenberg's time, so that they could continue to hate it more.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.mathstodon.xyz/media_attachments/files/116/408/024/388/646/773/original/18023d7809fbe947.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://mathstodon.xyz/users/mjd/statuses/116408054560179251</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mathstodon.xyz/users/mjd/statuses/116408054560179251</guid><dc:creator><![CDATA[mjd@mathstodon.xyz]]></dc:creator><pubDate>Wed, 15 Apr 2026 09:39:09 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 08:30:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> Do reporters share the tools used, or are there strong tool indicators in the reports?</p><p>Curious about which tool(s) are most successful, at least for cURL research.</p><p>I imagine in most cases reporters don't mention the tools used (especially if custom), which is unfortunate.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116407785784321316</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116407785784321316</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Wed, 15 Apr 2026 08:30:48 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 07:42:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> Can't wait for your next graph <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f913.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--nerd_face" style="height:23px;width:auto;vertical-align:middle" title="🤓" alt="🤓" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/louisbotha/statuses/116407597538706934</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/louisbotha/statuses/116407597538706934</guid><dc:creator><![CDATA[louisbotha@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 07:42:56 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 07:20:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> I see<br />- good ones using AI as part of a rigorous process with replication <br />- mediocre where someone asked an AI "Find me a CVE", submits the report without review or replication, and yet still expects credit </p><p>If "have write access to the filesystem" is a prerequisite to an exploit: it's not an exploit. You already have total ownership of the server</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116407509021332187</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/stevel/statuses/116407509021332187</guid><dc:creator><![CDATA[stevel@hachyderm.io]]></dc:creator><pubDate>Wed, 15 Apr 2026 07:20:25 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 07:19:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/varpie%40peculiar.florist">@<span>Varpie</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> 90% of the time it works every time. It probably improved dramatically, but still slop lingers?</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/edmcbane/statuses/116407505234700900</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/edmcbane/statuses/116407505234700900</guid><dc:creator><![CDATA[edmcbane@hachyderm.io]]></dc:creator><pubDate>Wed, 15 Apr 2026 07:19:27 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 07:18:55 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> Well, I guess you could quickly convince them otherwise with your "reports/ai-slop ratio" graph.</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/LangerJan/statuses/116407503114526909</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/LangerJan/statuses/116407503114526909</guid><dc:creator><![CDATA[langerjan@chaos.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 07:18:55 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 07:06:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/utopiah%40mastodon.pirateparty.be">@<span>utopiah</span></a></span> probably, but also because the AIs can't really tell</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116407454840516903</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116407454840516903</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 07:06:38 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 07:05:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> "they tend to overstress the vulnerability angle." which I imagine is simply because that's what the prompt suggested.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.pirateparty.be/users/utopiah/statuses/116407452130386833</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.pirateparty.be/users/utopiah/statuses/116407452130386833</guid><dc:creator><![CDATA[utopiah@mastodon.pirateparty.be]]></dc:creator><pubDate>Wed, 15 Apr 2026 07:05:57 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 07:05:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> yeah. Sorry. More like summary of the situation.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/grayrattus/statuses/116407450494208078</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/grayrattus/statuses/116407450494208078</guid><dc:creator><![CDATA[grayrattus@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 07:05:32 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 07:02:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/j_s_j%40mastodon.social">@<span>j_s_j</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <span><a href="/user/annika%40xoxo.zone">@<span>annika</span></a></span> month.</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://red.anthropic.com/2026/mythos-preview/" title="Claude Mythos Preview \ red.anthropic.com">
<img src="https://red.anthropic.com/2026/mythos-preview/FRT-Blog-Chart-CMP-Firefox-exploit@2x.png" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://red.anthropic.com/2026/mythos-preview/">
Claude Mythos Preview \ red.anthropic.com
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://red.anthropic.com/2026/mythos-preview/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://red.anthropic.com/anthropic-serve/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(red.anthropic.com)</span></p>
</a>
</div></p><p>Here you can read more.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/grayrattus/statuses/116407438976554636</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/grayrattus/statuses/116407438976554636</guid><dc:creator><![CDATA[grayrattus@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 07:02:36 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 07:02:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> I get this with fwupd too. Everything that's AI found is reported as a CVSS 10.0 CRITICAL vulnerability, and then you find out it's assuming the attacker has write access on /etc or something dumb like that.</p><p>At that point it's just a regular old typo bugfix like all the other thousands of unimportant commits.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/hughsie/statuses/116407438393099211</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/hughsie/statuses/116407438393099211</guid><dc:creator><![CDATA[hughsie@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 07:02:27 GMT</pubDate></item><item><title><![CDATA[Reply to The AI slop security reporting is basically extinct. on Wed, 15 Apr 2026 07:02:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/grayrattus%40mastodon.social">@<span>grayrattus</span></a></span> it was never my opinion as much as my summary of the situation... and the situation has changed quite drastically</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116407436827637430</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116407436827637430</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 07:02:03 GMT</pubDate></item></channel></rss>