Google pauses open-source product bug reports after surge in AI submissions
Google stopped accepting product vulnerability reports through its Open Source Software Vulnerability Rewards Program on October 1 after an influx of mostly invalid automated submissions. Reports about supply chain compromises remain eligible, according to The Hacker News, while Neowin reported that researchers were directed to Cloud VRP alternatives.
- According to Cyber Security News, Google plans a program update in the first quarter of 2027.
Covered by 5 publishers within 25 hours of the first report.
Reporting5
BleepingComputer Google halts open-source bug bounty program amid AI spam surge · Sergiu Gatlan
Cyber Security News Google Pauses Open-Source Bug Bounty Program After Flood of Invalid AI-Generated Reports · Abinaya
Android Headlines Google Freezes Open Source Bug Bounty Until 2027 Due to AI Spam Flood · Jean Leon
SecurityWeek Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports · Eduard Kovacs
The Hacker News Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports · info@thehackernews.com (The Hacker News)
Related
Topics Google