The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.

Recent analysis indicates that the application of large language models (LLMs) in the domain of vulnerability discovery and prioritization presents significant challenges for application security (AppSec) professionals. The primary issues identified are a high rate of false positives and a failure by these models to adequately consider the contextual nuances of security scans. This suggests that while LLMs offer potential, their current implementation in this area is not yet mature enough to reduce, and may even increase, the workload for human analysts.
The reported high false-positive rates mean that a substantial number of potential vulnerabilities flagged by LLMs are not, in fact, exploitable flaws. This necessitates manual review and verification by AppSec teams, diverting resources that would otherwise be spent on addressing genuine threats. This class of issue is common in automated security tools that rely on pattern matching or heuristic analysis, where a lack of deep understanding of code logic or system architecture can lead to misinterpretations.
Furthermore, the inability of LLMs to account for the context of security scans is a critical limitation. Context in AppSec can include factors such as the specific application environment, the intended functionality of a piece of code, the presence of compensating controls, or the overall threat model of a system. Without this contextual awareness, an LLM might flag a benign code pattern as a vulnerability or prioritize a low-risk issue over a more critical one, simply because it lacks the broader understanding of how the component fits into the larger system.
This limitation means that the output from LLM-driven vulnerability scanners often requires extensive human interpretation and refinement. AppSec professionals must manually sift through the reported findings, applying their expert knowledge of the application, its architecture, and its operational environment to distinguish between true vulnerabilities and false alarms. They also need to re-prioritize issues based on actual risk, rather than the raw output of the model.
For organizations considering or currently employing LLMs in their vulnerability management processes, typical mitigation guidance for this class of issue would involve robust post-processing and human oversight. This includes implementing a multi-stage review process where initial LLM findings are filtered and validated by other automated tools or, more critically, by experienced security analysts. Continuous feedback loops, where human corrections are used to retrain or fine-tune the LLM, could also help improve accuracy over time.
The findings highlight a broader trend in the cybersecurity industry regarding the integration of artificial intelligence and machine learning. While these technologies hold immense promise for automating and enhancing security operations, their deployment often uncovers practical limitations related to accuracy, contextual understanding, and the need for human expertise. The current state suggests that LLMs are best viewed as assistive tools that augment, rather than replace, the critical judgment and experience of AppSec professionals in the complex task of identifying and prioritizing software vulnerabilities.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.