MikeTrendsTrends right now

search

Open Source Vulnerability Reward Program

Trends

  1. 1
    Google pauses open source bug bounty program over flood of AI reports▼Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions✉newsTechnologySoftware27 min ago

    Google has temporarily frozen its open source bug bounty program, citing a significant rise in AI-generated submissions. The company says low-quality, automated vulnerability reports are overwhelming reviewers. The move highlights a growing problem for security teams as AI tools make it easy to mass-produce plausible-looking but often useless bug reports, forcing programs to reassess how they filter and reward legitimate research.

  2. 2
    AI slop floods Google bug bounty, forcing a freeze▼AI slop submissions force Google to freeze its open-source bug bounty✉newsTechnologySoftware27 min ago

    Google has suspended its open-source vulnerability reward program after a wave of low-quality, AI-generated bug reports overwhelmed reviewers. Security researchers say automated tools are mass-submitting plausible-sounding but useless vulnerability reports, drowning out genuine findings and making the program impossible to operate. The freeze highlights a wider problem: generative AI is now clogging bug bounty pipelines across the industry.

  3. 3

    Google has suspended part of its Open Source Vulnerability Reward Program as of October 1, halting payouts for product vulnerability submissions after a flood of low-quality, AI-generated invalid reports overwhelmed the program. The move covers Google-maintained open-source projects, with the company citing the burden of triaging junk submissions. The change has drawn discussion among developers concerned about security reporting quality.

  4. 4
    Google Narrows Open Source Bug Bounty Amid Invalid AI Reports▼Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports✉newsTechnologySoftware27 min ago

    Google is tightening the scope of its bug bounty program covering open source projects after being flooded with invalid, automated vulnerability reports. The flood of low-quality, likely AI-generated submissions has made it harder for reviewers to find genuine security flaws, prompting the company to restrict which projects and report types qualify for rewards.

  5. 5
    Google pauses open-source bug bounty program amid surge in submissions▼Google Just Hit Pause on Its Open-Source Bug Bounty Program —Explosive Surge in Submissions Has Left the✉newsTechnologySoftware27 min ago

    Google has temporarily paused its open-source bug bounty program, reportedly because an explosive surge in vulnerability submissions has overwhelmed its ability to process reports. The move has drawn attention in the security community, where researchers rely on the program to disclose flaws in widely used open-source projects and earn rewards for their findings.

  6. 6

    Google has temporarily paused its open source bug bounty program, citing a surge in submissions generated with AI tools. The company says low-quality automated reports have made it harder to identify genuine vulnerabilities worth rewarding. The move has sparked debate in the security community about whether AI-generated bug reports are overwhelming vulnerability disclosure programs across the industry, and when Google might resume the program.

  7. 7
    Google pauses open-source bug bounty amid fake AI reports▼Google pauses its open-source bug bounty after a flood of fake AI reports✉newsTechnologySoftware27 min ago

    Google has paused its open-source vulnerability reward program after receiving a wave of low-quality, AI-generated bug reports that overwhelmed reviewers. The company said the flood of bogus submissions made it impossible to separate genuine findings from automated junk. The pause highlights a growing strain that AI-slop reporting is putting on security incentive programs.

  8. 8
    Google pauses open-source bug bounty amid flood of AI reports●Google pauses its open-source bug bounty program after a flood of AI slop reports✉newsTechnologySoftware27 min ago

    Google has paused its open-source vulnerability reward program after being overwhelmed by low-quality, AI-generated bug reports. The company says automated submissions have made it hard to find genuine security flaws, so it is halting new rewards while it reassesses the program's rules and review process.

  9. 9

    Google has paused its open source bug bounty program, citing a flood of AI-generated spam reports. The program paid security researchers for finding vulnerabilities in open source projects. Reports say low-quality, automated submissions made it difficult for reviewers to identify genuine findings, prompting the suspension while the company reassesses how the program is run.

  10. 10
    Google Pauses OSS Vulnerability Reward Program Over AI Reports●Google Pauses OSS VRP Vulnerability Search Over AI Reports✉newsTechnologySoftware8 h ago

    Google has paused part of its Open Source Vulnerability Reward Program (OSS VRP), halting vulnerability search activities after a wave of AI-generated reports. The company is said to be dealing with a flood of low-quality or automated findings produced by artificial intelligence tools, prompting a temporary stop while it reassesses how such submissions are handled.

  11. 11

    Google has announced it is pausing its Open Source Vulnerability Reward Program through 2026. The program paid security researchers for finding bugs in Google's open-source projects, including Bazel, Angular, and Fuchsia. The pause means researchers cannot submit new reports for rewards during this period, and observers are questioning what the decision signals about Google's commitment to open-source security funding.

  12. 12
    Google pauses bug bounty program amid AI-generated spam▼Google pauses open-source bug bounty program after rise in AI spam submissions✉newsTechnologySoftware15 h ago

    Google has temporarily paused its open-source bug bounty program, which pays researchers for reporting security flaws in projects like Chromium and Bazel, after a wave of low-quality, AI-generated submissions flooded the system. The company says the volume of automated, invalid reports made it hard to review legitimate vulnerabilities, forcing the suspension.