PulseAugur
中
实时 16:01:22
English(EN) Google stopped accepting product-vulnerability reports through its Open Source Software VRP on Oct. 1 after a surge in automated submissions it says were mostly

Google因自动提交激增而暂停开源VRP

自10月1日起,Google已停止通过其开源软件漏洞奖励计划(VRP)接受产品漏洞报告。此决定是在自动提交报告数量显著增加之后做出的,该公司表示这些报告大部分无效。虽然仍接受供应链漏洞报告,但Google预计将在2027年第一季度更新该计划。该公司指出,虽然AI可以帮助发现漏洞,但可复现的证据对于维护者有效分类这些发现至关重要。 AI

影响 AI辅助的漏洞发现需要仔细验证,以避免给安全计划带来过重负担。

排序理由 一家公司正在改变其特定计划的政策,影响外部研究人员报告漏洞的方式。

在 Mastodon — mastodon.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

Google因自动提交激增而暂停开源VRP

本文如何被排名

Signal score
4 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
一家公司正在改变其特定计划的政策,影响外部研究人员报告漏洞的方式。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
policy, product, other
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
Standard
On-topic for AI-industry coverage; kept in the public index.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准。

报道来源 [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Google于10月1日停止通过其开源软件VRP接受产品漏洞报告,此前自动化提交激增,该公司称这些提交大部分是

    Google stopped accepting product-vulnerability reports through its Open Source Software VRP on Oct. 1 after a surge in automated submissions it says were mostly invalid. Supply-chain reports are still accepted, and Google plans an update in Q1 2027. AI can help find bugs, but fin…