The Decoder:AI News(RSS)
57AI 编辑部评分,满分 100

苹果漏洞赏金邮箱被AI垃圾报告淹没,真实macOS漏洞无人受理

2026-08-02 20:42· 39分钟前· Matthias Bastian
跳到正文
AI 摘要

苹果因大量AI生成的虚假漏洞报告堵塞审核流程,限制了安全研究员提交漏洞报告的数量。意大利初创公司Bynario用ChatGPT发现了一个可让攻击者完全控制设备的macOS严重漏洞,却因提交被拒而无法上报,CEO估计该漏洞黑市价值10万至20万美元。苹果已联系Bynario,同时自身正使用Anthropic和OpenAI的AI寻找漏洞,其最新更新修复数量是平时的五倍。

AI is a cybersecurity risk, but not the way you'd think. Apple is capping the number of bug reports security researchers can submit because a flood of low-quality, AI-generated reports with hallucinated vulnerabilities is clogging the review pipeline, the Financial Times reports.

That creates real security gaps. Italian startup Bynario used ChatGPT to find a serious macOS vulnerability that could give attackers full control over a machine but couldn't report it because Apple had blocked further submissions. CEO Alfredo Pesoli estimates the flaw's black-market value at $100,000 to $200,000. Apple has since reached out to Bynario.

Meanwhile, Apple itself is using AI from Anthropic and OpenAI to hunt for vulnerabilities, and its latest updates included five times as many fixes as usual. That raises the question whether bug bounty programs can survive long-term or whether big tech companies will handle vulnerability discovery on their own. Rafe Pilling of Sophos told the FT that bug bounty programs have gone from finding vulnerabilities to validating them "at machine speed."

AI News Without the Hype – Curated by Humans

苹果漏洞赏金邮箱被AI垃圾报告淹没,真实macOS漏洞无人受理

The Decoder:AI News(RSS)·2026-08-02 20:42·39分钟前·Matthias Bastian
阅读原文· the-decoder.com
AI 摘要

苹果因大量AI生成的虚假漏洞报告堵塞审核流程,限制了安全研究员提交漏洞报告的数量。意大利初创公司Bynario用ChatGPT发现了一个可让攻击者完全控制设备的macOS严重漏洞,却因提交被拒而无法上报,CEO估计该漏洞黑市价值10万至20万美元。苹果已联系Bynario,同时自身正使用Anthropic和OpenAI的AI寻找漏洞,其最新更新修复数量是平时的五倍。

原文 · 保持原样,未翻译

AI is a cybersecurity risk, but not the way you'd think. Apple is capping the number of bug reports security researchers can submit because a flood of low-quality, AI-generated reports with hallucinated vulnerabilities is clogging the review pipeline, the Financial Times reports.

That creates real security gaps. Italian startup Bynario used ChatGPT to find a serious macOS vulnerability that could give attackers full control over a machine but couldn't report it because Apple had blocked further submissions. CEO Alfredo Pesoli estimates the flaw's black-market value at $100,000 to $200,000. Apple has since reached out to Bynario.

Meanwhile, Apple itself is using AI from Anthropic and OpenAI to hunt for vulnerabilities, and its latest updates included five times as many fixes as usual. That raises the question whether bug bounty programs can survive long-term or whether big tech companies will handle vulnerability discovery on their own. Rafe Pilling of Sophos told the FT that bug bounty programs have gone from finding vulnerabilities to validating them "at machine speed."

AI News Without the Hype – Curated by Humans

阅读原文the-decoder.com