Select a theme from the list.
Insights

From our experts

Latest
Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development Platform
Security Insight

GitHub Reprices Security Research as Public Bug Bounties Fall

GitHub Reprices Security Research as Public Bug Bounties Fall
Photo by Rafael Minguet Delgado on Pexels

GitHub is reducing fixed payouts for its public bug bounty program while reserving substantially higher rewards for researchers invited into a private VIP tier. The change reflects growing pressure from AI-assisted vulnerability reports, but it may also make the program less attractive to skilled newcomers.

News Date: 2026-07-22

GitHub is restructuring its bug bounty economics, cutting public rewards while creating a larger financial gap between ordinary participants and researchers accepted into its invite-only VIP program. The new payment schedule takes effect on July 27, 2026, although reports submitted before that date will remain eligible for the previous reward structure.

Public rewards fall sharply

Under the new public schedule, low-severity vulnerabilities will pay $250, medium findings $2,000, high-severity reports $5,000 and critical vulnerabilities $10,000. The previous critical range began at $20,000 and could exceed $30,000, meaning the standard reward for a serious public submission is being reduced considerably.

The VIP program offers a different scale. Invited researchers may receive $1,000 for low-severity issues, $7,500 for medium findings, $20,000 for high-severity vulnerabilities and at least $30,000 for critical reports. GitHub says researchers can become eligible based on a history of accepted findings, although reaching the stated thresholds does not necessarily guarantee an invitation.

AI is changing vulnerability disclosure

The policy arrives as generative AI and automated code analysis make it easier to produce large numbers of plausible vulnerability reports. Maintainers increasingly face submissions that look convincing but lack validation, realistic impact or a working proof of concept. Triage capacity, rather than basic vulnerability discovery, is becoming the scarce resource.

GitHub has already demanded stronger evidence from researchers, including reproducible demonstrations and clear explanations of security impact. The latest reward changes appear designed to direct more attention toward established researchers who consistently provide high-quality reports.

The risk of creating a closed research circle

I believe GitHub is addressing a genuine problem, but the solution introduces a strategic trade-off. A private group may produce cleaner reports and faster communication, yet public bounty programs are valuable precisely because they attract people with different backgrounds, techniques and assumptions.

Lower rewards and strict submission limits may discourage capable newcomers who have not yet built a reputation on a particular platform. That could narrow the pool of people examining one of the world's most important software development ecosystems.

What a balanced program needs

  • Transparent and timely triage decisions.
  • A clear path from public participation to VIP status.
  • Appeal processes for disputed severity ratings.
  • Recognition for verified research, even when financial rewards are smaller.
  • Controls that filter automated noise without excluding new talent.

AI can accelerate vulnerability hunting, but human judgment still determines whether a weakness creates a meaningful attack path. GitHub's challenge is to reward that judgment without turning open security research into an insiders-only market.

Talk to our team →

Latest

Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesSep 10, 2026Unpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemSep 10, 2026Passkey Reset Scams Turn Strong Authentication Into Cloud PersistenceSep 10, 2026Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning4IDScan Lawsuits Put Mass Identity Collection Under the Microscope5Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching6Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System