This is sadly so relateable.
I feel like half my job these days is deciding which of the high/critical "security bugs" identified by someone's LLM is worth pushing back on because:
A. It isn't a bug, and just because it found a property with a similar name, perhaps it is an older feature flag and shouldn't be used as a default for customer accounts.
B. If I push back on all of these non-issues, I'll never have any time to get real work done. Of course the logging filters aren't checking and masking SSNs the app doesn't work with SSNs.