苹果漏洞赏金邮箱被AI垃圾报告淹没,真实漏洞无法上报
原标题:A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
AI 摘要
据《金融时报》报道,苹果公司因收到大量由AI生成的低质量漏洞报告而限制了安全研究者的提交数量,导致意大利初创公司Bynario发现的一个严重macOS漏洞无法上报,该漏洞在黑市价值高达20万美元。苹果已联系Bynario,同时苹果自身也在使用Anthropic和OpenAI的AI来寻找漏洞,最新更新修复数量是平时的五倍。这引发了对漏洞赏金计划长期可行性的质疑。
正文节选
A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop AI is a cybersecurity risk, but not the way you'd think. Apple is capping the number of bug reports security researchers can submit because a flood of low-quality, AI-generated reports with hallucinated vulnerabilities is clogging the review pipeline, the Financial Times reports. That creates real security gaps. Italian startup Bynario used ChatGPT to find a serious macOS vulnerability that could g