Apple limits bug reports after AI spam; ports and funds attacked

Apple capped bug-bounty submissions after a surge of AI-generated false reports. A cyberattack hit North Carolina ports on Aug. 4 and voice-phishing targeted several hedge funds.

Apple limited the number of vulnerability reports individual researchers can file in its bug-bounty program after security teams were overwhelmed by low-quality, AI-generated submissions. The company set a cap on submissions, will accept requests to raise the limit for legitimate high-volume researchers and has begun using automated tools to triage incoming reports. A security firm said it reached the new cap after using ChatGPT to surface more than 50 potential macOS issues, including a privilege-escalation finding that could not be immediately filed under the new rules.

North Carolina Ports detected a cyberattack on Aug. 4 that caused a systems-wide outage affecting the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port. Gates reopened the following day with expected delays after IT staff activated contingency procedures and contained the incident. Port officials said investigations are ongoing and it remains unclear whether sensitive data was taken as normal operations are restored.

A wave of voice-phishing attacks used synthetic voice technology to impersonate executives and trick employees into disclosing credentials or approving actions. Two Sigma reported it blocked an attempt with no impact to data or systems. Point72 notified investors it was reviewing an incident and found no initial evidence of client data theft. Other firms contacted about related activity declined to provide details.

Security professionals note that generative AI has made automated scanning and exploit generation more accessible, producing false positives and duplicated findings that increase the workload for triage teams. Separately, advances in synthetic audio have lowered the cost of creating convincing fake voices used in social-engineering attacks. Vendors and operators of critical infrastructure and financial firms are updating validation processes and incident response plans to manage higher volumes of automated reports and more realistic impersonation techniques.

Bug-bounty programs rely on outside researchers to find flaws and on internal analysts to validate those submissions. Apple’s new limits and its option to request exceptions are intended to change how incoming reports are processed while preserving channels for reporting legitimate, high-volume discoveries.

Articles by this author