Google has temporarily halted new product vulnerability reports through its Open Source Software Vulnerability Reward Program due to a surge in automated submissions. The company announced this pause on October 1, 2026, citing that most automated reports are invalid, often containing incorrect information or non-existent exploit paths. Google plans to rework the program and provide an update in early 2027, though supply-chain bug reports and the Patch Rewards Program remain active. AI
IMPACT AI-generated content is overwhelming security reporting channels, forcing a pause in bug bounty programs.
RANK_REASON A major tech company is pausing a significant program due to AI-related issues.
Read on Mastodon — fosstodon.org →
- anchoring
- blockchain
- ChatGPT
- Gemma
- Hackaday
- Hack a Day (unofficial)
- Mastodon
- Open Source Software Vulnerability Reward Program
AI-generated summary · Google Gemini · from 6 sources. How we write summaries →