(EN) Sourav Rudra, cURL Gets Rid of Its Bug Bounty Program Over AI Slop Overrun, in 24 gennaio 2026. URL consultato il 30 marzo 2026.
«just weeks into 2026, seven HackerOne reports came in within a 16-hour period in just one week. Some were actual bugs, but none of them were security vulnerabilities. By the time Daniel posted his recent weekly report, they'd already dealt with 20 submissions in 2026.
The main goal here is said to be stopping the flood of garbage reports. By eliminating the money incentive, they are hoping people (or bots?) will stop wasting the security team's time with half-baked, unresearched submissions.»