Tag
The article describes an individual who runs over 50 AI agents tuned for cybersecurity with a search index of CVEs, using a QLoRA-tuned GLM 5.2 model to continuously test production websites for vulnerabilities and earn money through bug bounties.
Bug bounty programs are being overwhelmed by a surge of low-quality AI-generated vulnerability reports, forcing platforms like HackerOne and Nextcloud to implement new filtering and validation measures. While the volume of submissions has jumped 76%, the rate of legitimate findings remains steady at 25%.
The article argues that the traditional 90-day responsible disclosure window is obsolete because LLMs enable rapid, simultaneous discovery of vulnerabilities, necessitating immediate patching of critical issues.