Loading market data...

Apple Bug Bounty Program Struggles With Flood of AI-Generated Reports

Apple Bug Bounty Program Struggles With Flood of AI-Generated Reports

The AI Bug Hunter Boom

->

एआई बग हंटर बूम

or more natural: "एआई बग हंटर का उछाल" but we can keep "बूम" as is. I'll use "एआई बग हंटर बूम" but maybe "एआई की बग हंटिंग में तेजी" - but to keep it simple, I'll use "एआई बग हंटर बूम". Next paragraph:

Security researchers have long used automated scanners to find bugs, but recent advances in AI have supercharged the process. Tools that can generate thousands of potential vulnerability reports per day are now common, and many of these are being submitted to Apple's bounty platform. The company, which pays researchers for discovering and responsibly disclosing security holes, is struggling to keep pace with the volume.

Translation:

सुरक्षा शोधकर्ता लंबे समय से बग खोजने के लिए स्वचालित स्कैनर का उपयोग करते रहे हैं, लेकिन एआई में हाल की प्रगति ने इस प्रक्रिया को और तेज कर दिया है। ऐसे उपकरण जो प्रतिदिन हजारों संभावित कमजोरी रिपोर्ट उत्पन्न कर सकते हैं, अब आम हैं, और इनमें से कई एप्पल के बाउंटी प्लेटफॉर्म पर जमा किए जा रहे हैं। कंपनी, जो सुरक्षा छिद्रों की खोज और जिम्मेदारी से खुलासा करने के लिए शोधकर्ताओं को भुगतान करती है, इस मात्रा के साथ तालमेल बिठाने में संघर्ष कर रही है।

Next paragraph:

Apple's bug bounty program, launched in 2016 and expanded over the years, offers rewards ranging from a few hundred dollars to over a million for critical flaws. But the program was designed for human researchers who manually probe for weaknesses, not for automated systems that can flood the queue with low-quality or false positives.

Translation:

एप्पल का बग बाउंटी प्रोग्राम, जो 2016 में शुरू हुआ और वर्षों में विस्तारित हुआ, कुछ सौ डॉलर से लेकर गंभीर खामियों के लिए दस लाख से अधिक तक के पुरस्कार प्रदान करता है। लेकिन यह प्रोग्राम मानव शोधकर्ताओं के लिए डिज़ाइन किया गया था जो मैन्युअल रूप से कमजोरियों की जांच करते हैं, न कि स्वचालित प्रणालियों के लिए जो कतार को निम्न-गुणवत्ता या गलत सकारात्मक परिणामों से भर सकती हैं।

Next heading:

Strain on the Bounty System

->

बाउंटी प्रणाली पर दबाव

Next paragraph:

The sheer number of AI-generated reports is creating a bottleneck. Apple's security team must triage each submission, verify its validity, and determine its severity. With the volume increasing, the risk of inefficiency grows. Legitimate vulnerabilities may take longer to be reviewed, and some could be missed entirely as analysts sift through mountains of automated output.

Translation:

एआई-जनित रिपोर्टों की भारी संख्या एक बाधा उत्पन्न कर रही है। एप्पल की सुरक्षा टीम को प्रत्येक सबमिशन का वर्गीकरण करना, उसकी वैधता सत्यापित करना और उसकी गंभीरता निर्धारित करनी होती है। मात्रा बढ़ने के साथ, अक्षमता का जोखिम बढ़ता है। वैध कमजोरियों की समीक्षा में अधिक समय लग सकता है, और कुछ पूरी तरह से छूट सकती हैं क्योंकि विश्लेषक स्वचालित आउटपुट के पहाड़ों की छानबीन करते हैं।

Next paragraph:

This isn't just a theoretical concern. Other companies with large bug bounty programs have already reported similar issues. The problem is that AI tools can generate reports that look plausible but are actually duplicates, irrelevant, or even malicious. Sorting the wheat from the chaff requires human expertise, and that expertise is a finite resource.

Translation:

यह केवल एक सैद्धांतिक चिंता नहीं है। बड़े बग बाउंटी प्रोग्राम वाली अन्य कंपनियों ने पहले ही समान मुद्दों की सूचना दी है। समस्या यह है कि एआई उपकरण ऐसी रिपोर्ट उत्पन्न कर सकते हैं जो प्रशंसनीय लगती हैं लेकिन वास्तव में डुप्लिकेट, अप्रासंगिक या यहां तक कि दुर्भावनापूर्ण होती हैं। भूसे से गेहूं अलग करने के लिए मानव विशेषज्ञता की आवश्यकता