A GitHub account published 50+ SQLite vulnerability advisories, but JFrog security researchers found that 54 were fabricated and one contained a real bug with unverified metadata. This incident highlights a systemic issue with automated vulnerability ingestion, where plausible-sounding fake advisories can cause organizations to waste time investigating and patching non-existent vulnerabilities.