search
bug bounty programs
Trends
- 1Google freezes open-source bug bounty amid AI-generated junk reports●Google freezes open-source bug bounty program amid flood of invalid AI slop
Google has suspended part of its Open Source Vulnerability Reward Program after a surge of low-quality, apparently AI-generated bug reports overwhelmed reviewers. From October 1, the program will no longer accept submissions for product vulnerabilities, with Google citing an influx of invalid reports as the reason. Commenters point to the episode as a side effect of automated AI tools mass-filing security bugs in hopes of bounties.
- 2Google Suspends Open Source Bug Bounties Amid Flood of AI Reports●Google Halts Open Source Bug Bounties Following Deluge of AI Slop
Google has paused its bug bounty program for open source projects after being overwhelmed by low-quality vulnerability reports generated with AI tools. The company says automated, spammy submissions have made it impossible to review genuine findings efficiently, forcing security teams to spend time filtering noise. The move highlights a growing problem for bug bounty programs as AI-generated slop floods vulnerability reporting pipelines.
- 3
Google has paused its open-source bug bounty program, with reports linking the decision to a flood of low-quality, AI-generated submissions. The program paid researchers for finding vulnerabilities in Google's open-source projects, and the influx of trivial or fabricated reports appears to have made it harder to identify genuine security flaws. Security watchers say the move highlights how generative AI tools are straining vulnerability disclosure programs across the industry.