AI slop submissions force Google to freeze its open-source bug bounty

Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), after a wave of invalid, AI-generated submissions swamped the engineers and open source maintainers who review them. The rules page for Google’s OSS VRP states that “as of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP.” “This pause is due to a significant rise in automated submissions, the vast majority … More →

This article has been indexed from Help Net Security

Read the original article: