Skip to content

All the news that matters, in plain English.

Latest
  1. Britain set to impose tariffs on Chinese electric cars, The Times reports
  2. Tories to pledge scrapping environment agencies and 'all in' for Heathrow third runway
  3. Flávio Bolsonaro officially wins Brazil's first round as pollsters miss badly; runoff confirmed for 25 October
  4. Brewers walk off Padres 4-3 in Game 2 to take 2-0 NLDS lead
  5. 49ers stay perfect at 4-0 with gritty 24-14 win over Broncos
  6. B-1 crews scrambled out of RAF Fairford before tankers were ready as threat intel spiked, NYT reports
  7. Bears flatten Jets 23-12 as Monangai runs for 146 yards and Bagent stars in relief of Williams
  8. Dodik claims sweeping victory as Bosnia vote delivers Serb presidency seat to ally Cvijanovic

Technology

Google freezes its open-source bug bounty after a flood of AI-generated reports

Google has paused new product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program, blaming a 'significant rise' in automated AI-generated reports, the 'vast majority' of them invalid.

Google has frozen new product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP), blaming a “significant rise” in automated, AI-generated reports, TechCrunch reported on Oct 4.

The company announced the pause on Oct 1 in posts on X and the program website, saying it will provide “an update” in the first quarter of 2027. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said, per TechCrunch. According to Tom’s Hardware, cited in the report, Google engineers and open-source maintainers were overwhelmed by reports that were invalid or contained hallucinations.

The freeze is narrower than a full shutdown: outstanding reports already in the system are unaffected, supply-chain disclosures under the OSS VRP remain open, and some product reports tied to Google Cloud repositories can still go through the separate Cloud VRP. Google is directing researchers toward its other vulnerability-reward programs and its Patch Rewards Program.

TechCrunch noted it had reported last year that cybersecurity experts were warning that AI “slop” posed a serious risk to bug bounty programs. The flood follows a pattern across the industry: Linux maintainers were inundated with bogus AI-generated CVE filings, and Intel recently froze its own bug bounty program amid the same AI-spam bottleneck, the Times of India reported.

More on this topic: all Technology stories

Get Flip News by email

This opens your email app — we add you manually. No account, no spam, no third parties.