← Back to stories
AI

Google freezes open-source bug bounty program amid flood of invalid AI slop submissions

Google has officially suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) — a bug bounty program — over an influx of invalid AI-driven reports. The company, in an official X post on October 1, encouraged participants to explore other VRP programs and committed to providing an update by the first quarter of 2027, while it reformats and works on this aspect of the program in the meantime.

AI data centers are swallowing the world's memory and storage supply

Demand for data center CPUs has surged, and AI agents are responsible

Chip scarcity assaults auto industry amid the worsening Nexperia and DRAM crisis

The suspension went into effect on October 1 — the day of the announcement — and does not affect product vulnerabilities submitted before that date. Google said it may still accept reports covering product vulnerabilities through the Cloud VRP, “for some Google Cloud repos impacting Google Cloud products.” …

You're reading a preview. The full article is published by Tom's Hardware on their website.

Read the full story on Tom's Hardware