High-Quality Chaos

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Daniel Stenberg, curl's maintainer, describes a new era of AI-assisted security research affecting open source projects. After shutting down curl's bug bounty due to low-quality AI-generated spam submissions, the project moved back to HackerOne in March 2026. The result: report volume doubled again, but quality is now high — confirmed vulnerability rates returned to ~15-16%. Nearly every report now shows signs of AI assistance. A Mastodon poll confirmed the same trend across dozens of major open source projects including Linux kernel, Firefox, git, Django, and many others. Curl alone may publish close to 50 CVEs in 2026, a record. The concern is that maintainer capacity won't keep pace with the flood of valid reports, and that bad actors can use the same AI tools to find vulnerabilities before patches are deployed.

4m read timeFrom daniel.haxx.se
Post cover image
Table of contents
No more AI slopHigher volume, higher qualityEverything is AI nowWe are not uniqueAn explosionWhere does it end?

Sort: