Skip to the stories
Tuesday, 6 October 2026
Saved

Next edition

0:50

Headlines

Cybercrime and Scams

Google freezes open source bug bounty program over invalid AI reports

Google has temporarily stopped accepting submissions to its open source vulnerability rewards program after receiving a surge of low quality, automated AI submissions.

FTMQ Security, written by our newsroom0 views

Share
Picture: Malwarebytes Labs

Google has paused product vulnerability submissions to its open source bug bounty program, known as OSS VRP, Malwarebytes Labs reported. The company stated that it took action to stop a flood of automated, AI generated vulnerability reports. Google confirmed that the vast majority of these recent submissions are not valid. [1]

According to Malwarebytes Labs, technology companies including Google and Microsoft are finding higher numbers of vulnerabilities in their own products through AI. However, public reporting programs are becoming overwhelmed by mass submissions of speculative, duplicated, or hallucinated findings. [1]

Similar issues have affected other software projects earlier this year. Malwarebytes Labs reported that in early 2026, the curl project ended its HackerOne bounty program following a wave of low quality submissions. [1]

Share

In short

  • Google has temporarily frozen vulnerability submissions to its OSS VRP open source bug bounty program.
  • The pause was caused by a sharp increase in automated and invalid AI generated reports.
  • Malwarebytes Labs noted that curl ended its HackerOne bounty program in early 2026 for similar reasons.

Sources

Every paragraph above points to the numbered items it rests on. Read the originals here.

  1. [1]Google pauses open source bug bounty program after rise in AI submissionsMalwarebytes Labs, 23h ago (the report this story comes from)

Background

  1. [2]List of Google Easter eggs on Wikipedia
  2. [3]Google on Grokipedia

Our newsroom writes these reports with the help of software, from the 3 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.

More in Cybercrime and Scams

Get the day in one email

Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments

Loading

Join the conversation

Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.

Already on the list? Enter the same address and we will send a sign-in link.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.