search
Google open source bug bounty program
Trends
- 1Google pauses open-source bug bounty over AI-generated junk reports●Google freezes open-source bug bounty program amid flood of invalid AI slop
Google has suspended part of its open-source vulnerability reward program, ending product vulnerability submissions from October 1, citing an influx of invalid reports generated by AI tools. Security researchers say automated tools are flooding bug bounty programs with low-quality submissions that waste reviewers' time, forcing companies to restrict or rework how they accept outside vulnerability reports.
- 2Google Pauses Open-Source Bug Bounty Program●Google Pauses Open-Source Bug Bounty Program Amid AI Slop
Google has paused its bug bounty program covering open-source projects, citing a flood of low-quality, AI-generated vulnerability reports that are overwhelming the review process. Security researchers say the influx of generic, machine-written submissions is making it harder to find genuine flaws, and the move has sparked debate about how AI-generated content is straining vulnerability disclosure programs.