Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Ninja Slushi makes vacation-worthy frozen drinks, and I highly recommend it (especially on sale)

    August 4, 2026

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)

    August 4, 2026

    Hashdex to Shut Down Bitcoin ETF After Struggling to Gain Assets

    August 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Ninja Slushi makes vacation-worthy frozen drinks, and I highly recommend it (especially on sale)
    • Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
    • Hashdex to Shut Down Bitcoin ETF After Struggling to Gain Assets
    • 518-million-year-old creature reveals the origins of spider fangs
    • Brazil’s mining agency under fire over corruption and omission probes
    • South America’s gas boom on the rise with Petrobras’ new discovery in Colombian waters
    • What’s Behind Indonesia’s Anti-Corruption Crusade?
    • Oil prices fall on hopes Strait of Hormuz could reopen
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    Apple’s AI Slop Problem Left a $200K macOS Exploit Unreported

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 4, 2026 Crypto & Blockchain No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In brief

    • Apple has limited how many bug reports a researcher can have open at once after a surge of AI-generated submissions.
    • Bynario says it found more than 50 macOS bugs in three weeks, including a chain that could hand an attacker full control of a Mac.
    • Apple’s security updates this week carried around five times as many fixes as previous cycles.

    Apple has capped how many vulnerability reports a researcher can file at once, after its security team was swamped by AI-generated submissions that invent flaws that do not exist, the Financial Times reported.

    The cap has already cost it a real one. Milan-based cybersecurity startup Bynario told the paper it used OpenAI’s ChatGPT to surface more than 50 bugs in the latest version of macOS over three weeks. Among them was a privilege escalation exploit chain, a class of flaw that hands an attacker unrestricted control of a machine.

    Bynario could not report it, because Apple had already refused further submissions. Chief executive Alfredo Pesoli put the exploit’s value on the criminal market at between $100,000 and $200,000, and said “maintainers and vendors have been flooded by the sheer amount of bugs” being uncovered. Apple told the FT it is now in contact with the firm and reviewing its work.

    Apple moved in June, adding a cap and a 30-day cool-off period on its security portal, with researchers required to apply for a bigger quota. Every alleged flaw still needs a human to confirm it, though Apple is using AI internally to triage the pile. Apple said it had “recently adjusted the number of new reports a researcher can have open at once,” and that researchers can ask for a higher limit at any time.

    The same tools are working for Apple. In security updates last week, it credited Anthropic and OpenAI software with surfacing flaws, and carried roughly five times the fixes of a normal cycle, according to the FT.

    A “submission flood”

    The issue of AI bug reporting volume has grown in recent months. In May, security firm Bugcrowd, whose clients include OpenAI, said submissions through its platform more than quadrupled across three weeks in March, and that most were fake. HackerOne and Nextcloud suspended their paid programs in April, with Nextcloud saying no rewards would be paid “regardless of severity” until it found a way to filter the low-effort reports.

    The volume is driven by the rewards on offer, with Meta, Microsoft, Apple and Crypto.com paying out at least $58 million between them in 2025, while Apple’s own top tier reaches $5 million for a single finding.

    At the same time, LLMs are becoming increasingly adept at spotting bugs. In March, Anthropic introduced Mythos, a cyber-focused model it initially restricted to selected technology companies, banks and researchers under Project Glasswing. Mozilla said it surfaced 271 vulnerabilities in Firefox during internal testing.

    In May, Vietnam-based security startup Calif said it had used a preview version to build the first public macOS kernel memory corruption exploit able to survive Memory Integrity Enforcement, the defence Apple announced last September as the biggest memory safety upgrade in the history of consumer operating systems. Calif found the bugs on April 25 and had a working exploit by May 1.

    Instead of filing a report, Calif carried the exploit to Apple’s California headquarters in person, saying it wanted to avoid “getting buried in the submission flood” that entrants in hacking contest Pwn2Own had been caught in. Bynario tried the portal three months later and could not get in.

    AI crypto threats

    As well as hunting down threats, AI is also being used to engineer exploits in the crypto space. Coldcard wallet manufacturer Coinkite has suggested that AI was likely used to uncover a bug in its open source firmware that sat unnoticed for five years, enabling attackers to steal more than $100 million from its hardware wallets.

    It comes two months after Zcash disclosed that researcher Taylor Hornby, working with Claude Opus 4.8, had found two lines of code in its Orchard shielded pool that allowed undetectable counterfeiting of ZEC for four years—prompting the privacy coin to roll out the Ironwood upgrade last month to address the vulnerability.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

    200k Apples exploit left macOS problem slop Unreported
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hashdex to Shut Down Bitcoin ETF After Struggling to Gain Assets

    At least 15 attackers exploited Coldcard vulnerability: Galaxy

    Sorry Everyone, but Bitcoin is Headed Down to $43,500: Michael Terpin

    Jim Cramer Plans to Sell Bitcoin Over Quantum Fears as BTC Rises 1.6%

    Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M

    Bitcoin self-custody: Coldcard flaw exposes a hidden risk

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Ninja Slushi makes vacation-worthy frozen drinks, and I highly recommend it (especially on sale)

    August 4, 2026

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)

    August 4, 2026

    Hashdex to Shut Down Bitcoin ETF After Struggling to Gain Assets

    August 4, 2026

    518-million-year-old creature reveals the origins of spider fangs

    August 4, 2026
    Latest Posts

    Oil prices hit $100 for the first time since May

    July 23, 2026

    Pew Survey: China May Be Liked More, but It Is Celebrating a Race It Never Ran

    July 23, 2026

    Yinson Production and PTSC’s FSO heads off to Southeast Asian oil project

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Ninja Slushi makes vacation-worthy frozen drinks, and I highly recommend it (especially on sale)

    August 4, 2026

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)

    August 4, 2026

    Hashdex to Shut Down Bitcoin ETF After Struggling to Gain Assets

    August 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.