リーディングビュー

Apple Limits Bug Bounty Submissions After Flood of AI Slop

✇Slashdot
著者: BeauHD

🤖 AI Summary

APPLEは、AIによって生成された低品質なバグ報告が大量に寄せられることで対応を難しくしている。セキュリティ企業のBynarioは、ChatGPTを使用して3週間で50以上のmacOS脆弱性を見つけたが、Appleが提出できるバグ報告数を制限したことから、重要な脆弱性(権限上昇型)を報告できなかった。

AppleはBynarioに対して連絡を取り、その報告書の審査を行っている。現在、研究者が開いた未解決のバグ報告の数に上限が設けられたが、重大な脆弱性を見逃さないよう必要に応じて上限を上げることができるという。

業界では「非常に難しい時期」にあるとし、大量の脆弱性により企業が脅威にさらされていると述べている。
Apple has capped the number of open bug-bounty reports researchers can submit after being flooded with low-quality and sometimes entirely fabricated vulnerabilities generated by AI. MacRumors reports: The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let an attacker get unrestricted access to a Mac, but was unable to report it because Apple limited the number of bug reports Bynario could submit. Bynario sent eight reports to Apple in 2025, and another five in 2026 before hitting a restriction. Bynario's founder said it is a "very difficult time in the industry" because companies are being "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing the company's submissions. While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability.

Read more of this story at Slashdot.

  •  

Massive Debian 13 Linux Kernel Security Update Patches 68 Vulnerabilities

Slashdot reader prisoninmate shares this report from 9to5Linux: Coming ten days after the previous Linux kernel security update, which only fixed 12 vulnerabilities that may lead to a privilege escalation, denial of service, or information leaks, the new Debian 13 Linux kernel security update is a massive one, and it patches no less than 68 security vulnerabilities in the Linux 6.12 LTS kernel. Debian 13 "Trixie" kernel security update are CVE-2026-64530, a use-after-free in the traffic-control subsystem leading to remote denial-of-service with potential for remote code execution, and CVE-2026-64531 (a.k.a. OVSwrap), a local-root vulnerability in the Open vSwitch datapath leading to local privilege escalation to root... All Debian 13 "Trixie" users are urged to update their installations to Linux kernel 6.12.100-1 as soon as possible.

Read more of this story at Slashdot.

  •  
❌