{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/maintainers-ai-bug-report-flood-2026/",
 "asOf": "2026-09-26",
 "id": "maintainers-ai-bug-report-flood-2026",
 "date": "2026-05-18",
 "datePrecision": "day",
 "title": "Maintainers report AI-generated vulnerability reports overwhelming kernel and bounty triage",
 "lane": "defense",
 "kind": "incident",
 "summary": "Help Net Security reported that Linus Torvalds described the Linux kernel security list as almost entirely unmanageable because of heavily duplicated AI-assisted reports, and that GitHub tightened its bug bounty submission requirements, with a GitHub engineer saying some programs elsewhere had shut down. The article also notes that curl ended bounty payments after a surge of low-quality AI reports.",
 "whyItMatters": "Human triage capacity, not discovery, is emerging as the bottleneck for AI-scale vulnerability finding.",
 "actors": [
  "linux-kernel",
  "curl",
  "github"
 ],
 "topics": [
  "vulnerability-discovery",
  "incident-reporting"
 ],
 "atlas": [
  "human-approver"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://lkml.org/lkml/2026/5/17/896",
   "publisher": "Linux kernel mailing list",
   "title": "Linux 7.1-rc4 (Linus Torvalds)",
   "date": "2026-05-17",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://github.blog/security/raising-the-bar-quality-shared-responsibility-and-the-future-of-githubs-bug-bounty-program/",
   "publisher": "GitHub",
   "title": "Raising the bar: quality, shared responsibility, and the future of GitHub’s bug bounty program",
   "date": "2026-05-15",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://www.helpnetsecurity.com/2026/05/18/problems-with-ai-assisted-vulnerability-research/",
   "publisher": "Help Net Security",
   "title": "AI is drowning software maintainers in junk security reports",
   "date": "2026-05-18",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Torvalds is quoted describing the kernel security list as almost entirely unmanageable, with enormous duplication from people finding the same bugs with the same tools.",
   "locator": "Opening paragraphs (quoting his kernel release-candidate note)"
  },
  {
   "fact": "GitHub began requiring submitters to validate AI-assisted findings and include a working proof of concept demonstrating exploitation potential and concrete security impact.",
   "locator": "Paragraphs on GitHub's bounty program"
  }
 ],
 "significance": 2,
 "fideQuestions": [
  "FID-076",
  "FID-077"
 ],
 "methods": [
  "ai-assisted-exploitation"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}