GitHub slashes public bug rewards to counter AI report flood
- Source
- The Register
- Time
- 5:56 PM
- Weight
- 94/100
GitHub has announced a significant restructuring of its bug bounty program, effective July 27, in response to an overwhelming volume of low-quality and AI-generated vulnerability reports. The Microsoft-owned platform is shifting its strategy to prioritize high-quality submissions from established security researchers while reducing the incentives for the general public.
According to GitHub, the changes aim to reduce administrative noise so that the security team can focus on legitimate, actionable security signals. The new system introduces a two-tier reward structure that drastically cuts payouts for public submissions.