Bug Bounties

GitHub to implement two-tier bug bounty program amid AI-generated report surge

(Credit: Ahmed – stock.adobe.com)

GitHub is launching a two-tier bug bounty program starting July 27, 2026, in response to an increase in low-quality, AI-generated vulnerability reports. This change aims to refine the quality of submissions and better reward dedicated researchers, with further coverage provided by Tech Radar.

The new system will feature a public program with fixed payouts for different severity levels: $250 for low, $2,000 for medium, $5,000 for high, and $10,000 for critical vulnerabilities. This replaces previous, wider payout ranges. An invitation-only VIP program will offer significantly higher rewards, approximately three to four times more than the public tier, for select researchers. GitHub is also introducing a HackerOne signal requirement for new participants to establish a track record, a measure likely intended to filter out automated or low-effort submissions. This strategic shift by the Microsoft-owned platform seeks to foster a more efficient and valuable bug bounty ecosystem, ensuring that serious security research is appropriately recognized and compensated.

Source: Tech Radar

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds