Computerworld · 4 min read

Apple and the invisible wolf: AI slop drowns real security threats

Apple and the invisible wolf: AI slop drowns real security threats

Apple has had to introduce a quota on security researcher reports because its systems are being overwhelmed by low-quality warnings generated by AI.  It’s a classic illustration of the rule of unintended consequences: a technology meant to help us has become a barrier to getting things done. After all, not only has AI driven the cost of consumer electronics higher, but it is also being used to identify and exploit security vulnerabilities — while also overwhelming security teams with low-grade reports, thus eroding their attention span. The cost of good intentions This is what’s happened at Apple, as security researchers use AI as a tool to identify new bugs. Perhaps the reports are well-intended. Hopefully, the researchers aren’t just motivated by the promise of easy bug bounties. Or maybe this is a cynical attempt to overwhelm platform security teams with low-grade bug reports — while holding back larger attacks for actual use by well-resourced state-backed actors. We can’t know whether attackers really are trying to overwhelm active platform defenses before going in for the kill. But given that it’s an actively used military strategy, it’s pretty hard to ignore the possibility. Apple’s response So, what’s happening at Apple? The company has put some limits in place to bug reporting as things got out of hand. It introduced a quota cap and a 30-day cool-off period for submitted reports, though researchers who exceed the cap can request an extension. This follows Apple’s recent decision to increase its top security bounty payout to $5 million for the most severe exploits. Apple has paid out more than $35 million to around 800 researchers since launching its bug bounty program. A Financial Times report tells us the many of the reports were about identical bugs, some already resolved, some trivial, but in combination comprising a fog of war that made it harder and more time-consuming to identify the really big flaws. The situation became so febrile the company made the decision to put limits in place in June. There is a little wriggle room to the approach: Apple has worked with the security community long enough to recognize some research teams. Those it trusts most can have their quota extended. Apple also deployed its own AI systems to triage incoming reports in an attempt to identify and remove AI-generated slop. The company also uses internal systems from Anthropic and OpenAI to help identify and fix vulnerabilities; that led to an extensive collection of fixes in its most recent software patch. The Times details an Italian company called Bynario, which identified a fairly nasty-sounding privilege escalation chain that lets attackers take complete control of a Mac. The company also reported a second bug, CVE-2026-43760, a macOS Screen Sharing flaw that allowed an authenticated VNC viewer to access protected data and create files with root privileges. Unfortunately, the hard-working research team was unable to report the first bug, as it had filed more than 50 reports in just three weeks thanks to AI. In other words, it’s possible some security researchers right now are unable to file warnings of critical vulnerabilities to Apple because the system is overwhelmed by slop. This is not just an Apple problem What makes this far more problematic is that it isn’t just Apple that is affected – security teams on multiple platforms are grappling with the same problem. Rafe Pilling, a security expert at Sophos, told the FT that bug bounty programs across the industry have had to shift from finding vulnerabilities to validating reports of them “at machine speed.” That follows comments from Jamf security expert Adam Boynton, who last week characterized AI use in security as, “an arms race between defenders and attackers who are both, increasingly, running the same kind of tools.” When it comes to platform security, it is possible that AI has added a new dimension of complexity to an already complex environment. Hopefully, the real threats will continue to be swiftly identified as they emerge, rather than being wrongly characterized as AI slop. When no one comes running To understand how this works, try reading Aesop’s fable about a shepherd boy who raised the alarm so often that when the real wolf arrived, no one came to help and the young shepherd? He was eaten. You can follow me on social media! Join me on BlueSky,  LinkedIn, Mastodon and subscribe to The Core.

This is a summary aggregated from Computerworld. Read the complete article on the original site:

Read full article at Computerworld

More AI & Machine Learning News