What it is
Argus and ByteRay publish AI-attributed vulnerability research through a proof-of-possession tracker. The public side exposes technical descriptions, disclosure state, affected projects, and CVE identifiers where assigned.
What is verified
The initial ledger entry covers three OP-TEE CVEs and one OpenBSD CVE. Separate no-CVE entries cover a disclosed Zabbix authorization flaw and a disclosed curl SSH connection-reuse flaw. Reserved and embargoed reports are not counted, and two Zabbix reports explicitly marked Won’t Fix remain excluded.
The platform attribution comes from Argus, while public CVE records and project material corroborate the CVE-backed subset. Entries are therefore labeled self-reported.