Close Menu
geekfence.comgeekfence.com
    What's Hot

    Meta’s new local AI model forces enterprises to rethink costs and ROI – Computerworld

    August 11, 2026

    An unreleased Anthropic model made progress on one of math’s biggest unsolved problems

    August 11, 2026

    Scientists discovered the brain doesn’t make decisions the way we thought

    August 11, 2026
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook Instagram
    geekfence.comgeekfence.com
    • Home
    • UK Tech News
    • AI
    • Big Data
    • Cyber Security
      • Cloud Computing
      • iOS Development
    • IoT
    • Mobile
    • Software
      • Software Development
      • Software Engineering
    • Technology
      • Green Technology
      • Nanotechnology
    • Telecom
    geekfence.comgeekfence.com
    Home»Cyber Security»Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
    Cyber Security

    Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits

    AdminBy AdminAugust 11, 2026No Comments3 Mins Read4 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports – many of which were found to be describing security flaws that simply didn’t exist.

    According to a report in the Financial Times, Apple has found itself facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely hallucinated bug reports.

    Unlike traditional spam, AI-generated bug reports include code which may be syntactically correct, references to genuine API calls, and plausible-sounding technical explanations of what is occurring.

    All of that could take an Apple engineer hours of time, configuring test environments, attempting to replicate flaws, only to ultimately verify that a flaw may not actually exist.

    But the hallucinated bug report may only have taken a few seconds for an amateur to generate and submit.

    In response to this problem, Apple has implemented “a cap and a 30-day cool-off period on submissions” through its bug-reporting portal, with any users who wished to submit further bug reports required to submit a special request.

    The Financial Times learnt about the Apple-imposed limit after Italian cybersecurity startup Bynario developed a custom AI scanning tool built on GPT-5.5 that submitted a burst of more than 50 macOS bug reports within just three weeks. Previously, without the assistance of AI, Bynario had filed only 13 bug reports across 2025 and early 2026.

    Bynario found it had automatically triggered Apple’s self-imposed limit on bug report submissions, and were locked out of the reporting portal just as they uncovered a critical zero day flaw in macOS that could give attackers full root control over a computer.

    Bynario chief executive and co-founder Alfredo Pesoli told the Financial Times that the exploit could fetch between US $100,000 and $200,000 on the computer underground.

    Apple has since had details of the flaw successfully submitted to it, but the very real concern is that genuine serious bug reports may not be received by the company due to the measures it has put in place to avoid poor-quality AI slop reports.

    Ironically, Apple itself is actively using AI to find vulnerabilities in its code. Its iOS 26.6 and macOS Tahoe 26.6 updates fixed around 100 security flaws, crediting AI models from Anthropic and OpenAI as well as their own internal AI triage tools.

    Apple is not the only company trying to deal with a deluge of automated AI-generated vulnerability reports, submitted in the hope of receiving generous bounties.

    GitHub, for instance, recently introduced a tiered bug bounty system specifically designed to filter out AI slop, by establishing an invite-only VIP group of verified researchers and limiting public submissions.

    The worry is that if reporting security holes in software becomes too frustrating for vulnerability researchers they may start weighing up their options. It is always preferable for a bug to be reported directly to the software developer rather than a third-party exploit broker.

    A third-party exploit broker is likely to offer upfront cash payouts for accepted submissions, with no caps on how many exploits are submitted, and no cool-off periods.

    Worst of all, they might have no qualms about selling details of a vulnerability to someone who might be intending to abuse it.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

    August 9, 2026

    Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

    August 8, 2026

    This month in security with Tony Anscombe – July 2026 edition

    August 7, 2026

    UK AI tests found 19 unauthorized agent actions

    August 6, 2026

    Beyond Volume: Countering the Stealth Tactics of Modern DDoS Attacks

    August 5, 2026

    Fake IRS letters target cryptocurrency holders

    August 4, 2026
    Top Posts

    Understanding U-Net Architecture in Deep Learning

    November 25, 202572 Views

    The Next Paradigm in Efficient Inference Scaling – The Berkeley Artificial Intelligence Research Blog

    May 16, 202640 Views

    Hard-braking events as indicators of road segment crash risk

    January 14, 202635 Views
    Don't Miss

    Meta’s new local AI model forces enterprises to rethink costs and ROI – Computerworld

    August 11, 2026

    “Meta just made agents a capital expense instead of an operating one,” Kenney said. “For…

    An unreleased Anthropic model made progress on one of math’s biggest unsolved problems

    August 11, 2026

    Scientists discovered the brain doesn’t make decisions the way we thought

    August 11, 2026

    Modern Risk Demands a Real-Time Foundation: The CRO’s Mandate

    August 11, 2026
    Stay In Touch
    • Facebook
    • Instagram
    About Us

    At GeekFence, we are a team of tech-enthusiasts, industry watchers and content creators who believe that technology isn’t just about gadgets—it’s about how innovation transforms our lives, work and society. We’ve come together to build a place where readers, thinkers and industry insiders can converge to explore what’s next in tech.

    Our Picks

    Meta’s new local AI model forces enterprises to rethink costs and ROI – Computerworld

    August 11, 2026

    An unreleased Anthropic model made progress on one of math’s biggest unsolved problems

    August 11, 2026

    Subscribe to Updates

    Please enable JavaScript in your browser to complete this form.
    Loading
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 Geekfence.All Rigt Reserved.

    Type above and press Enter to search. Press Esc to cancel.