Security researchers report that bug bounty platforms are being overwhelmed with low-quality, AI-generated vulnerability reports, straining resources and slowing legitimate submissions.
Bug bounty platforms designed to reward security researchers for finding vulnerabilities are experiencing a surge in AI-generated submissions that waste time and resources.
These automated reports often lack substance, contain duplicate findings, or describe non-existent vulnerabilities. Security teams now spend considerable effort filtering through noise to identify genuine security issues.
The influx stems from the accessibility of AI tools and the financial incentive of bounty programs. Attackers use AI to generate high volumes of submissions in hopes that some will qualify for payouts.
Platforms like HackerOne and Bugcrowd report the problem is "never-ending." Moderators face bottlenecks reviewing submissions, delaying payouts for legitimate researchers and creating friction in programs designed to improve security.
Companies are implementing stricter validation requirements and submission guidelines to combat the problem. Some platforms are exploring AI-based filtering tools to automatically screen low-quality reports before human review.
The challenge highlights the double-edged nature of AI proliferation: while it democratizes certain capabilities, it also enables low-effort abuse at scale.
Anthropic has signed out some Claude users and removed saved payment methods after infostealer malware on their computers hijacked active sessions to drain API usage credits. The company is issuing refunds for unauthorized charges.
Former NYC Traffic Commissioner Sam Schwartz warns that autonomous vehicle expansion creates significant cybersecurity risks, including the potential for bad actors to seize control of connected cars and weaponize them.
More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.
A new vulnerability called Omarchy allows any user-level process to gain root privileges through privilege escalation. The flaw has sparked significant discussion in security circles.