chiprook
← Security
SecurityOctober 8, 2026, 18:27

Google pauses open-source bug bounty over AI-generated reports

Google has temporarily stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program, citing a sharp rise in automated submissions that are mostly invalid. Supply-chain reports and the Patch Rewards Program remain open, with a program redesign promised in Q1 2027.

Google pauses open-source bug bounty over AI-generated reports
#Google#Go#Angular#Fuchsia
Read next
Security

Intel suspends bug bounty program that paid up to $100,000 per flaw — new Intigriti disclosure program offers no rewards

Security

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

Software

AI slop forces Turso to shut down its bug bounty program

Security

Epic pauses product development to fix MyChart security bugs