chiprook
← Security
SecurityOctober 7, 2026, 23:31

SecFoo: AI security scanner invented vulnerabilities without seeing code

An open-source CLI tool SecFoo was found to send prompts with no file contents in its no-coding-agent mode, causing the AI to report fake vulnerabilities in non-existent files. The bug was reproduced on a 7-file folder, and the broken implementation has since been removed.

SecFoo: AI security scanner invented vulnerabilities without seeing code
#SecFoo
Read next
Security

Wireshark 4.6.9 fixes 19 security vulnerabilities, including possible code execution

Security

Langflow CVE-2026-12944: Scanner Blocklist Gap Leads to Root Code Execution

Security

Stave scanner finds 47 security issues in default S3 configs of Mastodon, Discourse and Chatwoot

AI

Hermes Agent v0.21.5 lets AI agents use passwords without seeing them