Google benches open source bug bounty program following ‘significant rise’ in AI submissions

https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-2560-80.jpg
  • Google paused OSS bug bounty submissions after a surge of AI-generated, invalid reports
  • AI boosts vulnerability discovery but often produces flawed, incomplete, or hallucinatory findings
  • Rising AI-driven bounty spam has also overwhelmed curl maintainers and Linux security reviewers

Google has revealed it is pausing one of its bug bounty program and it’s all AI’s fault.

The company said its Open Source Software Vulnerability Rewards Program (OSS VRP) is being flooded with bogus and irrelevant submissions to the point where it was simply unmanageable.

As a result, the company is pausing accepting all submissions until the end of the year, taking the time to reassess the process and come up with new solutions.

Bug hunting in the age of AI

Generative Artificial Intelligence is supercharging defenders, discovering vulnerabilities at machine speed, making software better and more resilient against exploits and zero-day vulnerabilities.

A few frontier models, including the famed Mythos and...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more