GitHub restructures bug bounty program following flood of AI-generated reports
GitHub to launch two-tier (public and private) bug bounty schemes form July 27 2026 Change comes in response to rise in lower-quality, AI-generated reports VIP researchers will earn around 3-4x more per report GitHub has confirmed plans to evolve its bug bounty program into a two-tier system, which
<![CDATA[ <article> <ul><li><strong>GitHub to launch two-tier (public and private) bug bounty schemes form July 27 2026</strong></li><li><strong>Change comes in response to rise in lower-quality, AI-generated reports</strong></li><li><strong>VIP researchers will earn around 3-4x more per report</strong></li></ul><p>GitHub has confirmed plans to evolve its bug bounty program into a two-tier system, which will come into force for reports submitted on or after July 27, 2026.</p><p>Under the new scheme, the Microsoft-owned coding platform will add a lower-paying public program that's available to the wider research community, under a higher-paying invitation-only program.</p><p>Product Security Engineer Catherine Cassell <a href="https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/" target="_blank">explained</a> that the change comes in response to a growing backlog of low-effort, low-quality and AI-generated reports.</p><h2 id="github-complains-about-ai-generated-bug-reports">GitHub complains about AI-generated bug reports</h2><p>For the new public program, GitHub will replace payout ranges with a single payment for each severity, spanning $250, $2,000, $5,000 and $10,000 for low, medium, high and critical. Cassell said this would help researchers know in advance what a valid finding could be worth, and it would also give insiders less of a headache having to decide where a report sits within a range.</p><p>Notably, the payouts are much lower than before, with the previous ranges paying out $500-$1,000, $2,000-$5,000, $5,000-$20,000 and $10,000-$30,000.</p><p>Invited VIP researchers under the second plan will earn around 3-4x more than researchers under the other scheme, depending on bug severity.</p><p>GitHub is also adding a HackerOne signal requirement for new researchers, giving them four opportunities to "establish a track record" – likely another response to rising AI-generated reports, which are typically of lower value.</p><p>"We want to build a program that attracts the research we value, creates an experience that reflects how seriously we take this work, and upholds the trust researchers place in us every time they submit a report," Cassell concluded.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> </article> ]]>
Read the full article on TechRadar
Read Full Article →