GitHub slashes public bug bounty payouts as AI report flood buries its security team

https://image.theregister.com/5277108.jpg?imageId=5277108&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Dev ops

Code shack also putting new limits on first-time researchers, and reserving the biggest rewards for a hand-picked group of proven hunters

GitHub has decided that, if everyone with an AI chatbot can file a bug bounty report, it may as well stop paying them like seasoned security researchers.

Starting July 27, the Microsoft-owned code forge is overhauling its bug bounty program with a two-tier system that cuts rewards for public submissions while dangling much fatter payouts to a new invite-only group of researchers with proven track records.

At the same time, newcomers will find themselves capped on how many reports they can submit until they've demonstrated they can produce something worth reading.

The Microsoft-owned biz says that the shake-up is a response to the flood of low-effort and AI-generated reports now accompanying many bug bounty programs. Rather than paying more people to file more reports, GitHub wants to...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE