Google pauses open-source bug bounty program after rise in AI spam submissions

Google has paused product vulnerability submissions for its Open Source Software Vulnerability Reward Program (OSS VRP) after a flood of invalid, AI-generated reports overwhelmed security engineers and repository maintainers. The company announced the operational freeze in a post on X, directing security researchers toward its other active reward initiatives. Google stated that it will use the downtime to restructure the submission framework, with an official progress update slated for the first quarter of 2027.

What changes and what stays active

Read more

You may also like

Comments are closed.

More in IT