GitHub is launching a two-tier bug bounty program starting July 27, 2026, in response to an increase in low-quality, AI-generated vulnerability reports. This change aims to refine the quality of submissions and better reward dedicated researchers, with further coverage provided by Tech Radar.The new system will feature a public program with fixed payouts for different severity levels: $250 for low, $2,000 for medium, $5,000 for high, and $10,000 for critical vulnerabilities. This replaces previous, wider payout ranges. An invitation-only VIP program will offer significantly higher rewards, approximately three to four times more than the public tier, for select researchers. GitHub is also introducing a HackerOne signal requirement for new participants to establish a track record, a measure likely intended to filter out automated or low-effort submissions. This strategic shift by the Microsoft-owned platform seeks to foster a more efficient and valuable bug bounty ecosystem, ensuring that serious security research is appropriately recognized and compensated.Source: Tech Radar
Bug Bounties
GitHub to implement two-tier bug bounty program amid AI-generated report surge

(Credit: Ahmed – stock.adobe.com)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



