AI tools are democratizing and accelerating vulnerability discovery, but also overwhelming vulnerability management programs with false positives and 'AI slop.'
Security researchers utilize large language models (LLMs) to automate reconnaissance, reverse engineer APIs, and scan codebases at unprecedented speeds.
By leveraging AI tools, researchers are discovering flaws at accelerated rates, changing the calculus of effective bounty programs.
AI-powered bug hunting has changed the calculus of what makes for an effective bounty program by accelerating vulnerability discovery — and subjecting code maintainers to ballooning volumes of AI flaw-hunting slop.
Author's summary: AI-powered bug hunting accelerates vulnerability discovery.