Scaling security with responsible disclosure
Summary
OpenAI publishes an Outbound Coordinated Vulnerability Disclosure Policy outlining how it responsibly reports security vulnerabilities discovered in third-party software, anticipating increased vulnerability detection as AI systems become more capable at finding and patching security issues.
View Cached Full Text
Cached at: 04/20/26, 02:48 PM
Similar Articles
Outbound coordinated vulnerability disclosure policy
OpenAI has published its outbound coordinated vulnerability disclosure policy, outlining how it responsibly reports security vulnerabilities discovered in third-party software to vendors and open-source maintainers, including through AI-powered security analysis. The policy covers detection methods, peer review processes, and disclosure procedures under its Security Research team branded 'Aardvark'.
AI is breaking two vulnerability cultures
AI is disrupting traditional vulnerability disclosure cultures (coordinated disclosure vs. bugs-are-bugs) by accelerating the detection and exploitation of security flaws, making long embargoes less effective and forcing a need for faster, AI-assisted responses.
@AnthropicAI: Patching these vulnerabilities will make us safer. But the software industry will need to adapt to the volume of vulner…
Anthropic's Project Glasswing has used Claude Mythos Preview to find over 10,000 high or critical severity vulnerabilities in critical software, with partners like Cloudflare reporting a tenfold increase in bug finding rates, highlighting the shift from discovery to patching as the bottleneck.
Introducing the OpenAI Safety Bug Bounty program
OpenAI is launching a public Safety Bug Bounty program focused on identifying AI abuse and safety risks — including agentic risks, MCP vulnerabilities, and account integrity issues — complementing its existing Security Bug Bounty program. Researchers can submit issues that pose meaningful safety risks even if they don't qualify as traditional security vulnerabilities.
Preparing for malicious uses of AI
OpenAI co-authors a comprehensive paper forecasting malicious uses of AI and proposing mitigation strategies, developed in collaboration with leading research institutions. The work emphasizes acknowledging AI's dual-use nature, learning from cybersecurity practices, and broadening stakeholder discussions around AI security risks.