Surprisingly Useful AI Article Enhancements
A cybersecurity professional who was granted one of Australia’s most selective permanent visas has founded a Sydney-based company aimed at tackling the growing volume of low-quality and AI-generated vulnerability reports that are overwhelming security teams worldwide.
The Founder of the new company, Jacob Riggs, relocated from the United Kingdom to Sydney after receiving permanent residency through the 858 National Innovation visa program earlier this year. Within six months of landing, he has launched Bugtri, an AI-powered platform that automates the triage of vulnerability disclosure reports.
The project has been entirely bootstrapped and self-funded.
A growing problem for security teams
The platform arrives as cybersecurity teams and open-source software maintainers contend with a challenge brought about by generative AI: it has become far easier to produce vulnerability reports at scale, but someone still has to assess which of those reports represent genuine security issues.
Riggs describes the current state of vulnerability disclosure as an “AI arms race,” where AI-assisted report generation is outpacing the capacity of traditional human-led triage processes.
“AI is making it easier to generate reports at a scale that traditional human triage processes were never designed to handle,” he explained. “Bugtri uses AI to solve the very problem AI is creating.”
The issue has drawn the attention of industry bodies. The Open Source Security Foundation’s Vulnerability Disclosures Working Group launched dedicated work in 2026 to examine the impact of low-quality, AI-generated vulnerability reports and to develop guidance for organisations dealing with them.
How the platform works
Bugtri connects via OAuth to an organisation’s shared security mailbox. When a vulnerability report arrives, the platform automatically assesses it and returns a structured decision, risk score and summary to the inbox.
Sensitive information, including URLs and IP addresses, is sanitised before being passed to an AI provider for processing.
The platform does not attempt to replace security analysts. Instead, it is designed to filter and prioritise what reaches them. Incoming reports are automatically categorised and scored, duplicates are detected and uncertain assessments are flagged for human review rather than being dismissed outright.
The goal is to reduce the time security teams spend sorting through noise without allowing genuine vulnerabilities to be overlooked.
Early demand
Bugtri opened applications for early access three weeks ago. In that time, the platform received 27 applications, and 11 organisations are now actively using it during its early access phase.
Riggs believes the uptake reflects how widely the problem is felt across the industry.
A decade of vulnerability disclosure
The idea behind the platform draws on more than a decade of Riggs’ own experience finding and responsibly disclosing vulnerabilities to organisations around the world.
“After responsibly disclosing vulnerabilities to thousands of organisations over the past decade and observing the friction in their processes, I’m simply reconnecting with those teams and offering the automated triage solution they now need,” he noted.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
During the period in which he applied for his Australian visa, Riggs also responsibly disclosed a vulnerability in a live Australian Government system, which was subsequently acknowledged by the Department of Foreign Affairs and Trade.
Contributing to Australia’s cybersecurity landscape
Australia’s National Innovation visa, subclass 858, is a permanent visa for individuals with an internationally recognised record of achievement in their field. Candidates must first be invited by the Australian Government before they can apply.
Riggs indicated his motivation to build in Australia was shaped by the opportunity the visa represented.
“Australia welcomed me through the National Innovation Visa program, and I’ve tried to contribute back by creating an Australian company that now aims to solve a global cybersecurity problem,” he added.
The company has been accepted into the Australian Signals Directorate Partner Program. Riggs intends to make Bugtri’s capabilities available on a not-for-profit basis where they can support Australia’s cybersecurity interests.
Targeting small and medium organisations
Bugtri is primarily aimed at small and medium organisations, which often lack the resources to maintain large security teams capable of manually triaging high volumes of incoming vulnerability reports.
By automating the initial assessment and categorisation of those reports, the platform is intended to give smaller teams access to the kind of triage capability that would otherwise require significant headcount.
Last Updated on August 15, 2026 by Nick Ross



