The Lab · 2026-03-26 10:27:09 · GitHub Issues
A systematic review of Common Platform Enumeration (CPE) identifiers has uncovered widespread inaccuracies in how major development and infrastructure tools are mapped to known vulnerabilities. A spot-check of six critical tools—AWS, Eclipse, IntelliJ, Jenkins, Rancher, and Android Studio—revealed that several CPE vend...
The Lab · 2026-04-11 07:22:32 · GitHub Issues
A critical defect in the METATRON AI security scanner is generating false-positive vulnerability reports, raising serious questions about the tool's reliability for security assessments. The system's HTML output converts routine scanner anomalies and failed network interactions into definitive vulnerability claims, ass...
The Lab · 2026-05-07 21:01:39 · Ars Technica
Mozilla has disclosed that its internally developed Mythos scanning tool identified 271 vulnerabilities during an audit, with the organization characterizing its false positive rate as nearly negligible. The disclosure, which surfaced through a Hacker News discussion thread, positions Mythos as a high-precision additio...