search
Open Source Vulnerability Reward Program
Trends
- 1Google pauses open source bug bounty program over flood of AI reports▼Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google has temporarily frozen its open source bug bounty program, citing a significant rise in AI-generated submissions. The company says low-quality, automated vulnerability reports are overwhelming reviewers. The move highlights a growing problem for security teams as AI tools make it easy to mass-produce plausible-looking but often useless bug reports, forcing programs to reassess how they filter and reward legitimate research.
- 2AI slop floods Google bug bounty, forcing a freeze▼AI slop submissions force Google to freeze its open-source bug bounty
Google has suspended its open-source vulnerability reward program after a wave of low-quality, AI-generated bug reports overwhelmed reviewers. Security researchers say automated tools are mass-submitting plausible-sounding but useless vulnerability reports, drowning out genuine findings and making the program impossible to operate. The freeze highlights a wider problem: generative AI is now clogging bug bounty pipelines across the industry.
- 3Google pauses open-source bug bounty over AI-generated junk reports●Google freezes open-source bug bounty program amid flood of invalid AI slop
Google has suspended part of its Open Source Vulnerability Reward Program, ending product vulnerability submissions as of October 1, after a surge of invalid, AI-generated bug reports overwhelmed reviewers. The move highlights how low-quality automated security submissions are flooding bug bounty schemes, forcing companies to restrict or rethink how researchers can submit findings.
- 4
Google has paused its open source bug bounty program, citing a flood of AI-generated spam reports. The program paid security researchers for finding vulnerabilities in open source projects. Reports say low-quality, automated submissions made it difficult for reviewers to identify genuine findings, prompting the suspension while the company reassesses how the program is run.
- 5Google pauses open-source bug bounty program amid submission surge▼Google Just Hit Pause on Its Open-Source Bug Bounty Program —Explosive Surge in Submissions Has Left the
Google has temporarily paused its open-source bug bounty program, which pays researchers for reporting security vulnerabilities in its open-source projects. The company reportedly suspended submissions after an explosive surge in reports overwhelmed the program, leaving the company unable to process them. Security researchers are watching closely to see whether Google will resume payouts or restructure the initiative.
- 6Google pauses bug bounty program amid AI-generated spam▼Google pauses open-source bug bounty program after rise in AI spam submissions
Google has temporarily paused its open-source bug bounty program, which pays researchers for reporting security flaws in projects like Chromium and Bazel, after a wave of low-quality, AI-generated submissions flooded the system. The company says the volume of automated, invalid reports made it hard to review legitimate vulnerabilities, forcing the suspension.
- 7
Google has announced it is pausing its Open Source Vulnerability Reward Program through 2026. The program paid security researchers for finding bugs in Google's open-source projects, including Bazel, Angular, and Fuchsia. The pause means researchers cannot submit new reports for rewards during this period, and observers are questioning what the decision signals about Google's commitment to open-source security funding.
- 8Google pauses open-source bug bounty over AI-generated junk reports●Google freezes open-source bug bounty program amid flood of invalid AI slop submissions Google suspends product vulnerab
Google has suspended vulnerability submissions to its Open Source Software Vulnerability Reward Program after a wave of invalid, low-quality reports widely attributed to AI-generated research. The company says the flood of bogus submissions is overwhelming its review process. Security researchers are pointing to the suspension as an example of automated tools mass-producing submissions in pursuit of bounty payouts, undermining programs meant to reward genuine discoveries.
- 9
Google has temporarily paused its open source bug bounty program, citing a surge in submissions generated with AI tools. The company says low-quality automated reports have made it harder to identify genuine vulnerabilities worth rewarding. The move has sparked debate in the security community about whether AI-generated bug reports are overwhelming vulnerability disclosure programs across the industry, and when Google might resume the program.
- 10Google Pauses OSS Vulnerability Reward Program Over AI Reports●Google Pauses OSS VRP Vulnerability Search Over AI Reports
Google has paused part of its Open Source Vulnerability Reward Program (OSS VRP), halting vulnerability search activities after a wave of AI-generated reports. The company is said to be dealing with a flood of low-quality or automated findings produced by artificial intelligence tools, prompting a temporary stop while it reassesses how such submissions are handled.
- 11Google pauses open-source bug bounty amid fake AI reports●Google pauses its open-source bug bounty after a flood of fake AI reports
Google has paused its open-source vulnerability reward program after receiving a wave of low-quality, AI-generated bug reports that overwhelmed reviewers. The company said the flood of bogus submissions made it impossible to separate genuine findings from automated junk. The pause highlights a growing strain that AI-slop reporting is putting on security incentive programs.
- 12Google suspends open-source bug bounty amid flood of AI-generated reports●Google suspends open-source bug bounty program as AI slop overwhelms maintainers
Google has suspended its open-source bug bounty program, citing an overwhelming volume of low-quality, AI-generated vulnerability reports that burden maintainers. The decision highlights a growing problem across the security industry, as automated tools flood bug-tracking systems with junk submissions, making it harder for researchers to get legitimate findings reviewed and rewarded.