Help Net Security reported that Linus Torvalds described the Linux kernel security list as almost entirely unmanageable because of heavily duplicated AI-assisted reports, and that GitHub tightened its bug bounty submission requirements, with a GitHub engineer saying some programs elsewhere had shut down. The article also notes that curl ended bounty payments after a surge of low-quality AI reports.
Why it matters
Human triage capacity, not discovery, is emerging as the bottleneck for AI-scale vulnerability finding.
Key facts
As stated in the sources, with where to find them.
- Torvalds is quoted describing the kernel security list as almost entirely unmanageable, with enormous duplication from people finding the same bugs with the same tools.Opening paragraphs (quoting his kernel release-candidate note)
- GitHub began requiring submitters to validate AI-assisted findings and include a working proof of concept demonstrating exploitation potential and concrete security impact.Paragraphs on GitHub's bounty program
Findings that cite this record
Key questions this bears on
- Is AI shifting the balance between finding and fixing vulnerabilities?Discovery is ahead. AI finds real vulnerabilities faster than they are fixed, and simple checks overstate how often AI patches work.
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
Related records
May 22, 2026
Aug 4, 2026
Mar 6, 2026
Feb 20, 2026
Feb 5, 2026
Oct 30, 2025