chiprook
← Security
SecurityOctober 5, 2026, 21:06

Google Freezes Open Source Bug Bounty Until 2027 Over AI Spam Flood

Google has paused product vulnerability submissions for its Open Source Software Vulnerability Rewards Program until at least Q1 2027 after a flood of invalid AI-generated reports. Engineers and maintainers were spending too much time on thousands of bogus or hallucinated bugs instead of real security risks. The Patch Rewards program, paying up to $15,000 for verified patches, and Cloud VRP remain open.

Google Freezes Open Source Bug Bounty Until 2027 Over AI Spam Flood
#Google#Linux#Curl#Intel
Read next
Software

Greg Kroah-Hartman: Linux kernel copes with flood of LLM-found bugs

Security

Report: OpenAI agents flooded RubyGems with 2,000 spam gems in May

Software

AI slop forces Turso to shut down its bug bounty program

Security

Intel suspends bug bounty program that paid up to $100,000 per flaw — new Intigriti disclosure program offers no rewards