THE article discusses recent vulnerabilities (CVE-2026-18556, CVE-2026-34486, CVE-2026-9198) detected and highlights challenges faced by cybersecurity teams, particularly at Apple, due to the rise of AI-generated vulnerability reports. Apple has set stricter submission limits on its Bug Bounty Program to manage the influx of low-quality reports, enforcing a 30-day cooling-off period for researchers exceeding their quota.
This has led to critical vulnerabilities getting blocked from reporting, such as a serious flaw identified by Italian startup Bynario. The article concludes that the competition between AI-generated vulnerabilities and expert evaluation in cybersecurity is ongoing.