Google has suspended its Open Source Software Vulnerability Reward Program (OSS VRP) for product vulnerability submissions due to an overwhelming influx of invalid, AI-generated bug reports. The program, which incentivizes researchers to find security flaws in Google's open-source ecosystem, has been inundated with low-effort, AI-generated submissions that require significant manual validation. This suspension, effective October 1, will last until at least early 2027 while Google reformats the program, though supply chain reports and the Cloud VRP remain unaffected. AI
IMPACT Highlights the growing challenge of managing AI-generated noise in security and bug-reporting systems.
RANK_REASON A company is suspending a program due to AI-related issues, which is a common industry problem but not a core AI release or research.
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →