TAG

# Bug Bounty

← All tags · 1 post(s)

2026-08-03

Apple Put a Quota on Bug Reports — and 11 Flaws in the Same Patch Batch Were Found by AI

On August 2 the Financial Times reported that Apple has capped how many security reports a researcher can keep open at once and added a 30-day cool-off period, citing a flood of AI-assisted submissions. One week earlier, on July 27, Apple shipped 8 security advisories fixing 210 vulnerabilities — and 11 of them were found by AI: four credited to Claude, two to OpenAI Codex Security, three to the NVIDIA AI Red Team, two to Z.AI's GLM, and one screen-sharing privilege escalation to an automated engine called Atuin. The same day, GitHub halved its public bounty tiers and moved top payouts into an invite-only track. curl took the third road — leave the door open, remove the money — and reopened this morning after five weeks shut. Three projects, three different parts of the machine: one changed the incentive, one changed reputation, one changed the gate.

Apple Put a Quota on Bug Reports — and 11 Flaws in the Same Patch Batch Were Found by AI