GitHub restructures bug bounty program following flood of AI-generated reports
Date:
Fri, 24 Jul 2026 15:45:00 +0000
Description:
GitHub splits off open, public bug bounty programs from invite-only, VIP scheme which pays around 3-4x more.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter GitHub to launch two-tier (public and private) bug bounty schemes form July 27 2026 Change comes in response to rise in lower-quality, AI-generated reports VIP researchers will earn around 3-4x more per report GitHub has confirmed plans to evolve its bug bounty program into a two-tier system, which will come into force for reports submitted on or after July 27, 2026.
Under the new scheme, the Microsoft -owned coding platform will add a lower-paying public program that's available to the wider research community, under a higher-paying invitation-only program. Product Security Engineer Catherine Cassell explained that the change comes in response to a growing backlog of low-effort, low-quality and AI-generated reports. Latest Videos From TechRadar Watch full video here: GitHub complains about AI-generated bug reports For the new public program, GitHub will replace payout ranges with a single payment for each severity, spanning $250, $2,000, $5,000 and $10,000 for low, medium, high and critical. Cassell said this would help researchers know in advance what a valid finding could be worth, and it would also give insiders less of a headache having to decide where a report sits within a range.
Notably, the payouts are much lower than before, with the previous ranges paying out $500-$1,000, $2,000-$5,000, $5,000-$20,000 and $10,000-$30,000.
You may like Google will now pay up to $1.5 million for finding Android and Chrome security bugs AMD denies researcher $10,000 bug bounty reward despite spotting critical-severity issue Linus Torvalds says AI bug hunters have ruined Linux security mailing list
Invited VIP researchers under the second plan will earn around 3-4x more than researchers under the other scheme, depending on bug severity.
GitHub is also adding a HackerOne signal requirement for new researchers, giving them four opportunities to "establish a track record" likely another response to rising AI-generated reports, which are typically of lower value. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
"We want to build a program that attracts the research we value, creates an experience that reflects how seriously we take this work, and upholds the trust researchers place in us every time they submit a report," Cassell concluded. Follow TechRadar on Google News and add us as a preferred source
to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/github-restructures-bug-bounty-program- following-flood-of-ai-generated-reports
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)