惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
博客园_首页
Google DeepMind News
Google DeepMind News
博客园 - Franky
The GitHub Blog
The GitHub Blog
GbyAI
GbyAI
有赞技术团队
有赞技术团队
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
Recent Announcements
Recent Announcements
A
About on SuperTechFans
博客园 - 【当耐特】
博客园 - 三生石上(FineUI控件)
酷 壳 – CoolShell
酷 壳 – CoolShell
美团技术团队
罗磊的独立博客
IT之家
IT之家
博客园 - 聂微东
Stack Overflow Blog
Stack Overflow Blog
Jina AI
Jina AI
腾讯CDC
P
Proofpoint News Feed
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
AI is drowning software maintainers in junk security reports
Zeljka Zorz · 2026-05-19 · via Help Net Security

AI-assisted vulnerability research has exploded, unleashing a firehose of low-quality reports on overworked software maintainers who are wasting hours sifting through noise instead of fixing real problems.

AI-assisted vulnerability research

Linus Torvalds, the Linux kernel’s creator, says the flood has made the project’s security mailing list “almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools.”

Too many duplicates, and too much AI slop

“If you found a bug using AI tools, the chances are somebody else found it too,” Torvalds wrote in the note accompanying the latest Linux kernel release candidate.

“If you actually want to add value, read the documentation, create a patch too, and add some real value on *top* of what the AI did. Don’t be the drive-by ‘send a random report with no real understanding’ kind of person.”

Jarom Brown, Senior Product Security Engineer at GitHub, acknowledged last week that while AI lowering the barrier to entry for security research is a welcome development, his team is being inundated by submissions that fail to demonstrate any real security impact.

These include reports without a proof of concept, theoretical attack scenarios that don’t hold up under scrutiny, and findings already covered by GitHub’s published ineligible list.

And GitHub isn’t the only recipient of this unwanted deluge.

“Programs across the industry are grappling with the same challenge, and some have shut down entirely,” he said.

GitHub has stopped short of such a drastic measure, but is now requiring submitters to validate AI-assisted findings before sending them in.

Going forward, a complete submission must also include a working proof of concept demonstrating exploitation potential and concrete security impact.

Also, reports covering known ineligible categories will be closed as Not Applicable, which may impact the submitter’s HackerOne Signal and reputation, he added.

Finally, Brown urged researchers to be concise: bloated, AI-padded reports slow down triage and waste everyone’s time.

The researcher’s view

The collateral damage extends beyond the programs themselves. Shubham Shah, co-founder of Assetnote and a respected security researcher, says organizations are now taking far longer to review legitimate reports and act on real flaws, and that’s killing the feedback loop that keeps top researchers engaged.

While bug bounty platforms like HackerOne and Bugcrowd are trying to fight the onslaught of AI-created spam reports with AI and added controls, he says that “the joy of reporting vulnerabilities to bug bounties is quickly dissipating” – and not just for him.

“Hopefully the platforms actually work this out, but until then, I can’t see myself continuing to report high quality original research to certain programs where I have meaningfully contributed for a decade when they fail to understand the difference between myself and a researcher that doesn’t have any credibility,” he added.

In the near term, some experienced researchers may retreat to private vulnerability research and invite-only bounties.

Open source bears the brunt

The AI-powered “industrialization” of vulnerability discovery is currently a much bigger problem for open source projects than big organizations like Microsoft or Google, as they rely on volunteer maintainers, whose number and time is limited.

Those limitations have, for example, led the cURL project to stop accepting HackerOne submissions.

The project still accepts reports via GitHub or via email, but it no longer offers monetary rewards for security reports.

Curl lead developer Daniel Stenberg hopes the latter decision will remove the incentive for submitting AI slop, and believes that “the best and our most valued security reporters still will tell us when they find security vulnerabilities.”

In the meantime, the Open Source Security Foundation’s Vulnerability Disclosures Working Group is still seeking community feedback as it works to help open source maintainers tackle AI-generated junk reports. Its goals include compiling best practices, creating policy templates, and developing guidance to help maintainers spot and handle AI-assisted submissions.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!