Linux kernel czar says AI bug reports aren't slop anymore • The Register (Steven J. Vaughan-Nichols, 2026-03-26) – interview
Greg Kroah-Hartman can't explain the inflection point, but it's not slowing down or going away
… "Something happened a month ago, and the world switched. Now we have real reports." It's not just Linux, he continued. …
Two weeks later from SJVN:
Project Glasswing and open source software: The good, the bad, and the ugly – opinion
Just what FOSS developers need – a flood of AI-discovered vulnerabilities
He quotes David Wheeler, director of Open Source Supply Chain Security at the Linux Foundation (LF), which supports Glasswing:
… "Is there a risk of lock-in? Yes, that's always a risk. That said, I don't think the risk is as bad and we're working on ways to address this. …
"… the new open source software cyber reasoning system (OSS-CRS) emerged from AIxCC and is a standard orchestration framework for building and running LLM-based autonomous bug-finding and bug-fixing systems."
The second part was new to me.
AIxCC: AI Cyber Challenge | DARPA
Launched in 2023, the Artificial Intelligence Cyber Challenge (AIxCC) is a two-year competition that brings together the best and brightest in AI and cybersecurity to safeguard the software critical to all Americans. …
In the penultimate paragraph, SJVN agrees with the CFO of the Linux Foundation. There's real urgency.