'Almost entirely unmanageable': Linus Torvalds says AI bug hunters have
ruined Linux security mailing list
Date:
Mon, 18 May 2026 16:10:00 +0000
Description:
Torvalds says everyone is using AI to report on the same flaws, most of which have already been fixed.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Linus Torvalds warns
AIgenerated bug reports are overwhelming the Linux security mailing list with duplication and noise He urged researchers to add real value by creating patches instead of submitting random automated findings Similar concerns have already led projects like curl and HackerOnes Internet Bug Bounty Team to
shut down or restrict bug bounty programs The Linux security mailing list is now almost entirely unmanageable, since researchers started using Artificial Intelligence (AI) to flood it with useless reports, lead maintainer Linus Torvalds has warned.
After describing the latest release candidate as fairly normal in his latest weekly state of the kernel post, addressing things like drivers, networking, core kernel, and more, Torvalds stressed that some of the documentation updates might be worth highlighting. The continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools, he said. People spend all their time just forwarding things to the right people or saying "that was already fixed a week/month ago" and pointing to the public discussion. Latest Videos From You may like Linux rules on
using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the contribution' Over 29 million secrets were leaked on GitHub in 2025, and AI really isn't helping Hackers used AI to discover and weaponize a zero-day for the first time Entirely pointless churn Torvalds stressed these reports are entirely pointless churn, since most of the bugs
AI tools detects are pretty much by definition not secret, and that reporting that only makes duplication worse.
Besides complaining, Torvalds also gave a few concrete pointers, telling researchers to use AI in a way that is productive and makes for a better experience:
The documentation may be a bit less blunt than I am, but that's the core gist of it, he concluded. If you actually want to add value, read the documentation, create a patch too, and add some real value on *top* of what the AI did. Don't be the drive-by "send a random report with no real understanding" kind of person.
Torvalds is not the first person to point to people using AI to cause a flood of pointless reports. In late January this year, the developers of curl, the open source command-line tool and software library, announced they were killing their HackerOne bug bounty program for the same reasons. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting
your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
HackerOne also recently reported the Internet Bug Bounty Team, which it manages, would no longer reward researchers who identify and reward bugs. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/almost-entirely-unmanageable-linus-torv alds-says-ai-bug-hunters-have-ruined-linux-security-mailing-list
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)