{
  "id": 12172268,
  "title": "Google benches open source bug bounty program following ‘significant rise’ in AI submissions",
  "url": "https://urgent.news/2026/10/05/google-benches-open-source-bug-bounty-program-following-significant",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-05T14:50:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/google-benches-open-source-bug-bounty-program-following-significant-rise-in-ai-submissions"
  },
  "original_language": "en",
  "account": "Google has temporarily halted its Open Source Software Vulnerability Rewards Program (OSS VRP) due to a surge in AI-generated bug bounty submissions that are invalid or irrelevant. The company acknowledged that while AI enhances vulnerability discovery, it often produces flawed or incomplete findings, overwhelming the reviewers. This issue was compounded by AI-driven spam, overwhelming the curl maintainers and Linux security reviewers. Google's decision to pause the OSS VRP aims to reassess the process and develop new solutions. The company previously faced similar challenges with the curl project, which suspended its bug bounty program in early 2026 due to an influx of fabricated vulnerability reports. Linus Torvalds, the lead maintainer of the Linux security mailing list, also noted that AI-generated reports had made the security list \"almost entirely unmanageable\" due to duplication and low-quality submissions.",
  "summary": "Google says it will reassess in Q1 2027.",
  "key_points": [
    "Google paused Open Source Software Vulnerability Rewards Program",
    "AI-generated bug reports overwhelming reviewers",
    "Company reassessing process to develop new solutions"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}