Close Menu
NCIJ Network NCIJ Network
    What's Hot

    France’s Catholic Revival Is Fueling Its Far Right

    October 5, 2026

    Reform did not have only one health policy in the 2024 election – Full Fact

    October 5, 2026

    Norway plans temporary ban on smart glasses in some public places | Norway

    October 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • France’s Catholic Revival Is Fueling Its Far Right
    • Reform did not have only one health policy in the 2024 election – Full Fact
    • Norway plans temporary ban on smart glasses in some public places | Norway
    • Ex-Manchester leader defends deals with Man City owners
    • California Sen. Adam Schiff on AI, regulation, and corruption
    • Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity
    • NYSE owner and OKX plan 24/7 tokenized stock trading using Uniswap
    • A ‘phoenix’ planet was born from the ashes of its dead star
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, October 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 5, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions, saying a growing number of automated reports, most of them invalid, prompted the move.

    The pause was announced on X on October 1.

    “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said.

    Only product vulnerabilities are covered by the pause. According to Google, it has no impact on the program’s supply chain reports or on any pending reports.

    “This change does not affect product vulnerabilities submitted before October 1, 2026,” the company noted in an update on the program’s page.

    Some product vulnerability reports may still be eligible elsewhere. “For some Google Cloud repos impacting Google Cloud products we may still accept reports covering product vulnerabilities through the Cloud VRP,” Google said.

    Advertisement. Scroll to continue reading.

    Google wants bug hunters to look for impact in its other vulnerability reward programs and submit their findings there. Researchers can also turn to its Patch Rewards Program, which offers rewards for proactively improving the security of open source projects.

    “We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” Google said.

    [ Read: Will AI Kill the Bug Bounty Industry? ]

    Introduced in 2022, the OSS VRP pays researchers for vulnerabilities found in Google’s open source projects.

    The OSS VRP pause follows changes Google made in May to its Chrome and Android reward programs, in response to the growing use of AI tools for vulnerability discovery. 

    Standard Chrome payouts were reduced, as the company began favoring concise reports that provide concrete proof a bug exists. For Android, Google said it would prioritize vulnerability types that are harder for AI tools to find, and the top reward for a zero-click Pixel Titan M exploit with persistence went from $1 million to $1.5 million.

    In March, the Internet Bug Bounty (IBB) program run by HackerOne paused new submissions, saying the speed and volume of AI-assisted vulnerability discoveries had outpaced the open source community’s ability to deliver fixes.

    Related: Google Paid Out $17 Million in Bug Bounty Rewards in 2025

    Related: Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

    Related: OpenAI Launches Bug Bounty Program for Abuse and Safety Risks

    Automated Bounty Bug Google Invalid Narrows open reports source wave
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

    Open or closed AI? Learn what to build on at Disrupt 2026

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

    Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 

    Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    France’s Catholic Revival Is Fueling Its Far Right

    October 5, 2026

    Reform did not have only one health policy in the 2024 election – Full Fact

    October 5, 2026

    Norway plans temporary ban on smart glasses in some public places | Norway

    October 5, 2026

    Ex-Manchester leader defends deals with Man City owners

    October 5, 2026
    Latest Posts

    What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    France’s Catholic Revival Is Fueling Its Far Right

    October 5, 2026

    Reform did not have only one health policy in the 2024 election – Full Fact

    October 5, 2026

    Norway plans temporary ban on smart glasses in some public places | Norway

    October 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.