I've never once gotten a security vulnerability report in my software. Until this year. This year I've gotten 4 beg bounties (all of which are completely false/irrelevant reports). If you haven't read @troyhunt's post about Beg Bounties, I highly recommend reading it.
These people are actively harming software security.