AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

20:37 · July 22, 2026 · Hacker News AI Section

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, including those already in GitHub's growing triage queue, will retain the previous payout terms. GitHub said the

Summary

GitHub will halve its public bug bounty payouts starting July 27, 2026, moving critical reports from a previous range of $20,000–$30,000+ to a fixed $10,000 while shifting higher rewards to a permanent invite-only VIP tier that begins at $30,000 for critical findings. Low-, medium-, and high-severity public reports will also receive fixed payments that are roughly 50 percent lower than the prior ranges, with the company stating that fixed amounts reduce triage overhead and uncertainty. Reports already in the queue or submitted before the cutoff retain the old terms.

The changes aim to reduce noise from low-quality submissions and concentrate resources on researchers who demonstrate verified impact. Qualification for the VIP tier requires a minimum number of accepted reports at each severity level, after which invitees gain faster responses and direct access to GitHub’s security engineering team. The company has not published the exact HackerOne Signal threshold or time window for qualification.

These adjustments coincide with wider use of AI tools that lower the cost of generating candidate vulnerabilities. Google’s Gemini 3.5 Flash Cyber model, released the day before GitHub’s announcement, is designed for repeated scans of code paths and can produce working exploits in hours; internal tests showed it identifying more confirmed V8 issues than earlier models. Similar automation has already affected other projects: the curl maintainer ended cash rewards in January 2026 after the confirmed-vulnerability rate dropped below 5 percent amid rising AI-generated reports, though quality later improved once cash incentives were removed.

The result is a clearer separation between first-pass discovery, which AI can now perform at scale, and the remaining scarce skills of chaining findings across trust boundaries, proving material impact, and validating product-specific attack paths. GitHub continues to accept AI-assisted research provided researchers reproduce and verify the results themselves.

Why it matters

This article is highly relevant for security professionals as it highlights how AI is fundamentally altering the economics and operations of vulnerability management and bug bounties. Dutch enterprises running bug bounty programs or utilizing AI for code security must adapt to these shifts to effectively manage AI-generated reports and leverage new AI security models.

More in this beat
bug-bountygeminigithubHackerOneopen-source-securitythreat-and-vulnerability-updates
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

20:23 · July 20, 2026

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Directly addresses AI-specific security risks and privacy threats via malware in AI tooling ecosystems, with actionable recommendations applicable to Dutch teams using GitHub, MCP servers, or agentic AI. Aligns with EU data protection needs due to data-stealing payloads.

Relevance 85 · Audience 90

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

11:13 · June 9, 2026

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

Python is the foundational programming language for AI development. Security professionals in the Dutch AI market must be aware of PyPI supply chain attacks to secure their AI development environments, protect proprietary models, and prevent credential theft.

Relevance 65 · Audience 85

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

19:23 · August 20, 2026

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

The article provides crucial updates on privacy-enhancing technologies for AI that are vital for GDPR compliance in the Netherlands. It also alerts security professionals to emerging AI-driven threats, such as uncensored LLMs and AI models capable of autonomous vulnerability exploitation, which require immediate defensive consideration.

Relevance 85 · Audience 95

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

13:30 · August 6, 2026

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

Directly addresses AI security risks from prompt injection and memory poisoning with actionable guidance for professionals. Applicable to Dutch/EU teams using commercial AI tools, aligning with GDPR and AI Act compliance needs. Provides concrete detection patterns and policy recommendations.

Relevance 85 · Audience 90

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

14:51 · July 31, 2026

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

This article highlights how AI and LLMs are fundamentally changing the cybersecurity landscape by accelerating vulnerability discovery and exploitation. Dutch security professionals must adapt their vulnerability management strategies to handle the increased volume of AI-driven threat disclosures in ubiquitous enterprise software.

Relevance 85 · Audience 95

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

10:04 · July 28, 2026

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

This article is highly relevant for security professionals as it demonstrates the practical application of AI in offensive cybersecurity and vulnerability research. It highlights a specific Linux kernel vulnerability that Dutch enterprises must patch, while also signaling the evolving threat landscape where AI accelerates exploit development.

Relevance 75 · Audience 90

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

17:09 · July 21, 2026

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

This article is highly relevant for Dutch security professionals as it introduces a state-of-the-art AI tool for automated vulnerability discovery and patching. Given the strict EU regulatory landscape (like NIS2 and the Cyber Resilience Act), leveraging such AI capabilities will be critical for Dutch enterprises and government bodies to proactively secure software supply chains.

Relevance 90 · Audience 95

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

11:07 · July 20, 2026

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

This article is highly relevant for security professionals as it demonstrates a real-world case of AI being weaponized to automate and manage cyberattacks. Understanding these AI-driven tactics is crucial for Dutch enterprises to update their threat models and develop countermeasures against highly adaptable, AI-assisted threat actors.

Relevance 85 · Audience 95