AI-Generated Bug Reports Flood HackerOne: Security Researcher Calls for Action

2025-05-07
AI-Generated Bug Reports Flood HackerOne: Security Researcher Calls for Action

Security researchers have discovered a surge in AI-generated, false vulnerability reports flooding bug bounty platform HackerOne. These reports, often perfectly worded and formatted, lack actual security value, wasting security researchers' time and potentially obscuring real vulnerabilities. Researchers are calling on HackerOne to strengthen its review mechanisms and crack down on this behavior, suggesting solutions like bond systems or leveraging existing network infrastructure for review. This is a worrying trend potentially impacting open-source projects on a large scale.

Development