Urgent.News

What's breaking now, across thousands of outlets.

AI

Google praised AI for finding bugs. Now it has too many reports, not enough bugs

AI made bug hunting easier. Now Google is dealing with the fallout.

Google praised AI for finding bugs. Now it has too many reports, not enough bugs

Google has stopped accepting product vulnerability reports through its OSS VRP (Open Source Software Vulnerability Reward Program) due to a surge in automated submissions filled with invalid data, primarily AI-generated reports. The company had previously warned in March about the rapid increase in AI-generated bug reports, including hallucinated bugs and low-impact issues.

This development comes at a time when Google has been actively promoting the benefits of AI in software security, noting that AI agents are finding bugs that humans often miss, uncovering vulnerabilities hidden deep within code for years, and scanning massive codebases at a pace far exceeding that of human security teams. Executives at Google have even dubbed some of these AI tools as game-changers in the field.

However, this success story has a twist. The very AI that has proven so effective in bug hunting has led to Google having to close one of the main channels for reporting vulnerabilities. The search giant has temporarily halted the acceptance of product vulnerability submissions through its OSS VRP, citing the overwhelming volume of automated submissions as the reason behind this decision.

Written by urgent.news from Android Authority's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at androidauthority.com →

More in AI

Stop Letting AI Agents Perform Compliance Theater

If you ask an LLM to perform a compliance audit, it will likely fail. Not because it lacks knowledge, but because it lacks discipline.

  • AI agents give vague compliance responses due to lack of discipline.
  • Five common mistakes in LLM reasoning about compliance frameworks.
  • Compliance Governance Prover addresses regulations, controls, evidence, gaps, and accountability.

I tested 11 AI models on Indian GST, UPI and lakh-crore. Three famous ones got Puducherry wrong.

This is a submission for the Kaggle Benchmarking Challenge What I Benchmarked I build software for Indian small businesses (POS, billing, payments), and this month I've been contributing Kestra…

  • Three renowned AI models incorrectly identified Puducherry as a Union Territory
  • Smaller open-weight models like gpt-oss-20b and Gemma 4 performed better
  • Open-weight models offered better value for handling Indian GST and UPI tasks

Walled AI Guardrails in Practice

By Yaala Labs Walled AI gives us a clean, practical safety + PII masking pipeline for agent input/output flows. It is easy to integrate, fast to test, and useful for production guardrail baselines.

  • Walled AI provides fast safety checks and built-in PII masking for AI agents.
  • Integration is straightforward with a simple API surface for operationalization.
  • Limitations include lack of placeholder memory across calls and no field-level PII masking.

Can an AI catch the catch? I benchmarked 14 models on bounty fine print

This is a submission for the Kaggle Benchmarking Challenge What I Benchmarked I'm a solo developer in Vietnam. For the last few weeks I've been hunting paid work online: bug bounties, hackathons…

  • Six AI models scored 40/40 correct answers in the benchmark
  • "Free" in bounty listings proved most effective trap for models
  • Open bounties with linked pull requests hardest case for models

More from Tuesday 6 October →