344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth193
AI Infrastructure & MLOps175
Writing & Content Creation204
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support133
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Google paused its open source bug bounty program until next year, saying automated AI submissions flooded the system and most were not valid.
In short: Google paused its open source bug bounty program after a surge of automated, mostly invalid reports that it linked to AI.
Google has paused its Open Source Software Vulnerability Rewards Program, a program that pays people for reporting security flaws in Google-supported open source software.
A bug bounty program is like a reward board, companies offer money to anyone who finds a real problem and reports it responsibly. Open source software means the code is shared publicly, so anyone can inspect it, like a recipe that anyone can read and reuse.
Google said the pause started on October 1. It plans to share an update in the first quarter of 2027.
Google blamed a “significant rise in automated submissions,” and said most of these reports were not valid. Other reporting said engineers and project maintainers were overwhelmed by reports that were incorrect or included “hallucinations,” which is when an AI tool confidently makes up details that are not true.
Google encouraged participants to consider its other bug bounty programs in the meantime.
Bug bounties help companies fix security issues before they hurt users. If the reporting system gets flooded with low quality submissions, it can slow down the work of finding and fixing real problems. It is similar to a 911 line getting jammed with prank calls, the real emergencies still happen, but they are harder to reach in time.
Source: TechCrunch AI