The curl bug bounty program has ended after maintainers faced a surge of low-quality, AI-generated vulnerability reports. The project’s lead developers said the flood of submissions consumed time and energy without improving security. The decision highlights how artificial intelligence has started to reshape bug bounty ecosystems, often creating more noise than value for small open-source…