Curl will stop bug bounties program due to avalanche of AI slop



  • Curl ends HackerOne bug bounty due to fake and AI-generated vulnerability reports
  • Developers say incentives led to abuse, overwhelming the security team with invalid submissions
  • From February 2026, bug reports move to GitHub with no financial rewards

The developers of curl, the open source command-line tool and software library, are killing their HackerOne bug bounty program because they are being flooded with fake problems and vulnerabilities.

In a new advisory published on GitHub, it was said that the program is being sunsetted at the end of January, 2026.


https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img