search
bug bounty programs
Trends
- 1Google pauses open-source bug bounty over AI-generated junk reports▼Google freezes open-source bug bounty program amid flood of invalid AI slop
Google has suspended part of its open-source vulnerability reward program, ending product vulnerability submissions from October 1, citing an influx of invalid reports generated by AI tools. Security researchers say automated tools are flooding bug bounty programs with low-quality submissions that waste reviewers' time, forcing companies to restrict or rework how they accept outside vulnerability reports.
- 2Google Pauses Open-Source Bug Bounty Program▼Google Pauses Open-Source Bug Bounty Program Amid AI Slop
Google has paused its open-source bug bounty program, with reports attributing the decision to a flood of low-quality, AI-generated vulnerability reports overwhelming the program's reviewers. The move highlights a growing burden on security teams as automated tools churn out submissions that must be triaged. Security commentators are debating whether the change signals wider trouble for crowd-sourced vulnerability disclosure.
- 3OpenAI Awards $300 Bounty for Authentication Bypass Flaw●OpenAI Pays Researcher $300 for Major Authentication Bypass Bug
OpenAI paid a researcher a $300 bounty for reporting a major authentication bypass vulnerability. The relatively modest payout for a flaw classified as significant has drawn attention, with many pointing out that comparable bugs often earn far larger rewards from other technology companies running bug bounty programs.
- 4Google suspends part of its open source bug bounty▼Why Google is suspending part of its open source bug bounty
Google is suspending part of its bug bounty program covering open source projects. The move means security researchers will temporarily no longer be rewarded for reporting certain vulnerabilities in Google's open source software. The announcement is drawing attention from the security community, with researchers questioning the implications for vulnerability disclosure and Google's commitment to open source security.
- 5Google Halts Open Source Bug Bounties Over AI-Generated Reports▼Google Halts Open Source Bug Bounties Following Deluge of AI Slop
Google has paused parts of its open source bug bounty program, saying it has been flooded with low-quality, AI-generated vulnerability reports. The company says the volume of spammy submissions is wasting reviewers' time and crowding out legitimate security research. The move has reignited debate about how AI-generated content is overwhelming platforms designed around human effort.