BleepingComputer πŸ” Cybersecurity πŸ‘ 0 πŸ“– 2 min read

Google halts open-source bug bounty program amid AI spam surge

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]

Google halts open-source bug bounty program amid AI spam surge

  • October 5, 2026
  • 04:27 AM

Google

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports.

The company's OSS VRP incentivizes security researchers to responsibly disclose security flaws across open-source projects maintained by Google, including Golang, Angular, Bazel, Protocol Buffers, Fuchsia, and critical third-party dependencies, as well as repository settings like GitHub actions, application configurations, and access control rules.

Google launched the OSS VRP in August 2022 with rewards ranging from $100 to $31,337, and noted that the program would focus on security flaws with the most significant impact on the software supply chain.

"We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports," the company said. "Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."

However, researchers can still submit security patches for open-source software through the Google Patch Rewards Program (which offers bounties of up to $15,000 for high-impact fixes) and report vulnerabilities in Google Cloud open-source repositories that affect Cloud products through the company's Cloud VRP.

Google added that it's now working on readjusting the OSS VRP to address the automated submission issues, with more information on what will change to be provided next year.

"We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027," Google added in an update on the Bug Hunters website. "In the meantime, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program. This change does not affect product vulnerabilities submitted before October 1, 2026."

Google OSS VRP freeze

Since launching its first VRP in 2010, Google has rewarded thousands of security researchers with over $81.6 million. In 2025, it awarded a record-breaking $17.1 million to more than 700 security researchers, a 40% increase from 2024, when it awarded $12 million in total.

Google isn't the first to shut down a bug bounty program in the last year because of an ongoing onslaught of poor-quality AI-generated reports.

In January, the maintainer of the curl command-line utility and library ended the project's HackerOne security bug bounty program after being overwhelmed by a massive stream of AI slop vulnerability reports.

More recently, in mid-September, Intel also removed all financial rewards for security flaws in its software, firmware, hardware, and services reported on its Intigriti bug bounty program. However, Intel has yet to explain this decision.

While it has yet to take a similar move, Microsoft also warned in May that AI tools now help surface far more vulnerabilities, which will lead to the "pace and breadth of vulnerability discovery [..] increasing across the software industry" and "can raise operational demands."

Last month, Microsoft released patches for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.

Build your security blueprint for AI-powered attacks

Join Mikko HyppΓΆnen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat
πŸ“° Read the original article on BleepingComputer

Originally published by BleepingComputer. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.