Cybersecuritynews OpenAI Launches Safety Bug Bounty Program to Address AI Abuse Risks
Article Content
- •OpenAI's Safety Bug Bounty program launched on March 25, 2026.
- •The program focuses on AI abuse and safety risks, complementing the existing Security Bug Bounty.
- •Researchers can report issues via Bugcrowd, with specific scenarios outlined for eligibility.
On March 25, 2026, OpenAI announced the launch of its Safety Bug Bounty program aimed at identifying AI abuse and safety risks across its products. This initiative complements the existing Security Bug Bounty program, which has rewarded 409 security vulnerabilities since April 2023. The new program encourages researchers to report issues that pose meaningful abuse and safety risks, even if they do not qualify as security vulnerabilities. Specific scenarios include agentic risks and integrity violations, while general content-policy bypasses without demonstrable impact are excluded. Researchers can submit issues through Bugcrowd, and submissions will be triaged by OpenAI's teams. The program aims to foster collaboration with the safety and security research community to enhance AI system security. OpenAI also conducts private bug bounty campaigns targeting specific harm types.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…