Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Circle and Tether find common ground against MiCA’s bank reserve rules

    October 5, 2026

    Rare Southern African succulent listed as critically endangered amid mining threat

    October 5, 2026

    Oil Company Plugs Well That Posed Threat to Enid, Oklahoma’s Water — ProPublica

    October 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Circle and Tether find common ground against MiCA’s bank reserve rules
    • Rare Southern African succulent listed as critically endangered amid mining threat
    • Oil Company Plugs Well That Posed Threat to Enid, Oklahoma’s Water — ProPublica
    • Fixing Global Malaise: How Rebuilding Local Communities Can Counter Populism
    • Ex-prince Andrew launches bid to ‘quash’ Epstein-affair search warrants
    • Badenoch ally attacks Burnham’s ‘hope hard enough’ economic message as ‘absolutely mad’
    • Shadow chancellor to address Tory conference as he claims slashing red tape could cut cost of new houses by £50,000 – UK politics live | Politics
    • Diagnostic Challenges for ECB Monetary Policy
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, October 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Google halts open-source bug bounty program amid AI spam surge

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 5, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports.

    The company’s OSS VRP incentivizes security researchers to responsibly disclose security flaws across open-source projects maintained by Google, including Golang, Angular, Bazel, Protocol Buffers, Fuchsia, and critical third-party dependencies, as well as repository settings like GitHub actions, application configurations, and access control rules.

    Google launched the OSS VRP in August 2022 with rewards ranging from $100 to $31,337, and noted that the program would focus on security flaws with the most significant impact on the software supply chain.

    “We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports,” the company said. “Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”

    However, researchers can still submit security patches for open-source software through the Google Patch Rewards Program (which offers bounties of up to $15,000 for high-impact fixes) and report vulnerabilities in Google Cloud open-source repositories that affect Cloud products through the company’s Cloud VRP.

    Google added that it’s now working on readjusting the OSS VRP to address the automated submission issues, with more information on what will change to be provided next year.

    “We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” Google added in an update on the Bug Hunters website. “In the meantime, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program. This change does not affect product vulnerabilities submitted before October 1, 2026.”

    Google OSS VRP freeze

    Since launching its first VRP in 2010, Google has rewarded thousands of security researchers with over $81.6 million. In 2025, it awarded a record-breaking $17.1 million to more than 700 security researchers, a 40% increase from 2024, when it awarded $12 million in total.

    Google isn’t the first to shut down a bug bounty program in the last year because of an ongoing onslaught of poor-quality AI-generated reports.

    In January, the maintainer of the curl command-line utility and library ended the project’s HackerOne security bug bounty program after being overwhelmed by a massive stream of AI slop vulnerability reports.

    More recently, in mid-September, Intel also removed all financial rewards for security flaws in its software, firmware, hardware, and services reported on its Intigriti bug bounty program. However, Intel has yet to explain this decision.

    While it has yet to take a similar move, Microsoft also warned in May that AI tools now help surface far more vulnerabilities, which will lead to the “pace and breadth of vulnerability discovery [..] increasing across the software industry” and “can raise operational demands.”

    Last month, Microsoft released patches for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Bounty Bug Google halts OpenSource Program spam surge
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Alleged ShinyHunters Leader Arrested in Jordan

    Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

    Can an Open Model Do Security Research? Cantina’s apex-flash-1 Solves 40 of 60 Held-Out Bug Tasks

    Citrix patches NetScaler SAML zero-day exploited in attacks

    Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

    Anthropic asks Claude users to share voice data for AI model training

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Circle and Tether find common ground against MiCA’s bank reserve rules

    October 5, 2026

    Rare Southern African succulent listed as critically endangered amid mining threat

    October 5, 2026

    Oil Company Plugs Well That Posed Threat to Enid, Oklahoma’s Water — ProPublica

    October 5, 2026

    Fixing Global Malaise: How Rebuilding Local Communities Can Counter Populism

    October 5, 2026
    Latest Posts

    Bald Range Wildfire Forces Evacuation of 18,000 in British Columbia

    August 9, 2026

    Amazon deforestation alerts fall to lowest level since 2013, Brazilian data show

    August 9, 2026

    Institutional bear market: Why Bitcoin’s downturn is different

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Circle and Tether find common ground against MiCA’s bank reserve rules

    October 5, 2026

    Rare Southern African succulent listed as critically endangered amid mining threat

    October 5, 2026

    Oil Company Plugs Well That Posed Threat to Enid, Oklahoma’s Water — ProPublica

    October 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.