✉news TechnologySoftware first seen 1 d ago, last 6 h ago, peak #2
Google Narrows Open Source Bug Bounty Over Automated Reports
Original: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google is tightening the scope of its bug bounty programme covering open source projects after a surge in invalid reports generated by automated vulnerability-scanning tools. The flood of low-quality, machine-generated submissions has made it harder to review genuine security findings, prompting the company to restrict which projects and issues qualify for rewards. Security researchers say the change reflects a broader industry challenge as AI-assisted tooling produces mass duplicate or bogus reports.
Why now: Automated and AI-generated vulnerability reports are overwhelming bug bounty programmes industry-wide, and Google's policy change is a notable response.
GoogleGoogle Bug Bountyopen source community
Rank over time, top of the chart is #1. 17 snapshots from 1 d ago to 6 h ago.
Evidence
- Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports · SecurityWeek
- Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports · SecurityWeek
API: https://socialmediatrends-api.osmike.com/v1/trends/1129525