AI-Generated Fake Reports Disrupt Bug Bounty Programs

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Generative AI tools are flooding bug bounty platforms with low-quality and fake vulnerability reports, overwhelming companies like Bugcrowd, Curl, and Nextcloud. This surge has forced some organizations to suspend their programs, causing operational disruption and wasted developer resources in the cybersecurity sector.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions generative AI tools producing fake bug reports that overwhelm bug bounty programs, leading to the suspension of these programs and wasted developer time. This is a direct harm caused by the use of AI systems, disrupting critical cybersecurity infrastructure and operations. The harm is realized and ongoing, not merely potential. Hence, this qualifies as an AI Incident due to the direct negative impact caused by AI-generated false reports on cybersecurity operations and infrastructure.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Digital security

Affected stakeholders
BusinessWorkers

Harm types
Economic/Property

AI system task:
Content generation


Articles about this incident or hazard