$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

AI-assisted researchers at Google flooded Vercel with reports of Linux kernel vulnerabilities, forcing the company to automate vulnerability triage and improve its bug bounty program.

Bottom line: Multiple Linux kernel vulnerabilities were identified and fixed in a single 30-day period.

What's happening: Google researchers used AI-powered tools to scan Vercel's codebase, identifying 27 vulnerabilities with a total CVSS score of 74.5. The $1 million sandbox challenge was launched to encourage researchers to identify vulnerabilities in the Linux kernel.

What to do: Security leaders should review their bug bounty programs to ensure they are effective in identifying vulnerabilities like those identified in this challenge.

Source: SecurityWeek