GitHub is scaling back its bug bounty program by replacing cash rewards with swag for low-impact reports, citing a surge in AI-generated, low-quality submissions over the past year. The platform clarified that reports describing scenarios where users voluntarily interact with malicious content don't represent GitHub security failures. GitHub still welcomes AI-assisted research but requires human review before submission. The trend is industry-wide: Curl eliminated its bounty program, HackerOne paused payouts, Google restricted its OSS vulnerability rewards, and Linus Torvalds flagged the Linux kernel security list as nearly unmanageable due to AI-generated duplicate reports. Analysts warn the shift from cash to swag could shrink the pipeline of new security researchers, while benefiting experienced ones through faster triage and payouts.

5m read timeFrom csoonline.com
Post cover image
972 Impressions