GitHub, the world's leading platform for software development and version control, has announced a significant overhaul of its public bug bounty programme. The company is reducing the monetary rewards offered for identifying vulnerabilities and introducing stricter criteria for participation, particularly impacting new researchers. This strategic shift is largely attributed to an overwhelming influx of AI-generated security reports, which have reportedly buried GitHub's internal security teams.
Under the revised programme, payouts for publicly reported bugs will be scaled back. Furthermore, first-time security researchers will face new limitations, making it harder for them to earn rewards. GitHub intends to concentrate its most substantial bounties on a hand-picked group of established and proven security hunters, suggesting a move towards a more exclusive and curated approach to vulnerability disclosure.
The decision underscores a growing challenge within the cybersecurity landscape: the double-edged sword of artificial intelligence. While AI offers powerful tools for security analysis and threat detection, it also enables the rapid generation of numerous, often low-quality, vulnerability reports. These reports, many of which may be duplicates or false positives, consume valuable time and resources from human security teams who must triage and verify each submission.
Industry experts suggest that the sheer volume of AI-generated reports has made it increasingly difficult for platforms like GitHub to distinguish genuine, high-impact threats from trivial or non-existent issues. By adjusting its bounty programme, GitHub aims to incentivise more focused, high-quality research from experienced individuals, thereby reducing the noise and allowing its security personnel to concentrate on critical vulnerabilities.
This development could have broader implications for the bug bounty ecosystem, potentially prompting other major tech companies to reassess their programmes in light of the proliferation of AI tools. It highlights the ongoing need for human expertise in cybersecurity, even as automation becomes more prevalent, and the challenge of adapting traditional security models to the rapid advancements in AI technology.