Briefly
- Apple has restricted what number of bug stories a researcher can have open without delay after a surge of AI-generated submissions.
- Bynario says it discovered greater than 50 macOS bugs in three weeks, together with a series that would hand an attacker full management of a Mac.
- Apple’s safety updates this week carried round 5 occasions as many fixes as earlier cycles.
Apple has capped what number of vulnerability stories a researcher can file without delay, after its safety workforce was swamped by AI-generated submissions that invent flaws that don’t exist, the Monetary Instances reported.
The cap has already price it an actual one. Milan-based cybersecurity startup Bynario informed the paper it used OpenAI’s ChatGPT to floor greater than 50 bugs within the newest model of macOS over three weeks. Amongst them was a privilege escalation exploit chain, a category of flaw that fingers an attacker unrestricted management of a machine.
Bynario couldn’t report it, as a result of Apple had already refused additional submissions. Chief government Alfredo Pesoli put the exploit’s worth on the prison market at between $100,000 and $200,000, and stated “maintainers and distributors have been flooded by the sheer quantity of bugs” being uncovered. Apple informed the FT it’s now in touch with the agency and reviewing its work.
Apple moved in June, including a cap and a 30-day cool-off interval on its safety portal, with researchers required to use for a much bigger quota. Each alleged flaw nonetheless wants a human to substantiate it, although Apple is utilizing AI internally to triage the pile. Apple stated it had “not too long ago adjusted the variety of new stories a researcher can have open without delay,” and that researchers can ask for a better restrict at any time.
The identical instruments are working for Apple. In safety updates final week, it credited Anthropic and OpenAI software program with surfacing flaws, and carried roughly 5 occasions the fixes of a traditional cycle, in response to the FT.
A “submission flood”
The difficulty of AI bug reporting quantity has grown in current months. In Could, safety agency Bugcrowd, whose shoppers embrace OpenAI, stated submissions by its platform greater than quadrupled throughout three weeks in March, and that almost all had been faux. HackerOne and Nextcloud suspended their paid packages in April, with Nextcloud saying no rewards can be paid “no matter severity” till it discovered a approach to filter the low-effort stories.
The amount is pushed by the rewards on supply, with Meta, Microsoft, Apple and Crypto.com paying out at the least $58 million between them in 2025, whereas Apple’s personal high tier reaches $5 million for a single discovering.
On the similar time, LLMs have gotten more and more adept at recognizing bugs. In March, Anthropic launched Mythos, a cyber-focused mannequin it initially restricted to chose know-how firms, banks and researchers beneath Mission Glasswing. Mozilla stated it surfaced 271 vulnerabilities in Firefox throughout inside testing.
In Could, Vietnam-based safety startup Calif stated it had used a preview model to construct the primary public macOS kernel reminiscence corruption exploit in a position to survive Reminiscence Integrity Enforcement, the defence Apple introduced final September as the most important reminiscence security improve within the historical past of client working techniques. Calif discovered the bugs on April 25 and had a working exploit by Could 1.
As an alternative of submitting a report, Calif carried the exploit to Apple’s California headquarters in particular person, saying it wished to keep away from “getting buried within the submission flood” that entrants in hacking contest Pwn2Own had been caught in. Bynario tried the portal three months later and couldn’t get in.
AI crypto threats
In addition to looking down threats, AI can be getting used to engineer exploits within the crypto house. Coldcard pockets producer Coinkite has steered that AI was seemingly used to uncover a bug in its open supply firmware that sat unnoticed for 5 years, enabling attackers to steal greater than $100 million from its {hardware} wallets.
It comes two months after Zcash disclosed that researcher Taylor Hornby, working with Claude Opus 4.8, had discovered two strains of code in its Orchard shielded pool that allowed undetectable counterfeiting of ZEC for 4 years—prompting the privateness coin to roll out the Ironwood improve final month to handle the vulnerability.
Every day Debrief Publication
Begin day-after-day with the highest information tales proper now, plus authentic options, a podcast, movies and extra.

