Feeds2.Feedburner GitHub Revamps Bug Bounty Program Amid AI Report Surge
Article Content
- •GitHub's bug bounty payouts are significantly reduced for public submissions.
- •A new VIP tier rewards seasoned researchers with higher payouts.
- •Newcomers face limits on report submissions until they prove their capability.
GitHub is overhauling its bug bounty program effective July 27, 2026, to address a surge in low-quality submissions, particularly those generated by AI. The new structure introduces a two-tier system: a public program with significantly reduced payouts and an invite-only VIP tier for seasoned researchers. Public submissions will see rewards cut from as much as $30,000 for critical vulnerabilities to a maximum of $10,000. The VIP tier offers higher payouts, with critical vulnerabilities earning at least $30,000. GitHub aims to reduce administrative noise and focus on quality submissions. New researchers will face limits on report submissions until they demonstrate a history of valid findings. The changes follow earlier adjustments aimed at improving report quality and managing the influx of AI-assisted submissions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…