[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fu1-4ANnp6meAOVAVaoDHimXadTpiHzRBzNoRHh8bT2w":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"b3828651-233c-41af-b288-b115ca24d30f","Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports","google-narrows-open-source-bug-bounty-amid-wave-of-invalid-automated-reports-a5e296","Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The post Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports appeared first on SecurityWeek.","Google has temporarily halted submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) due to a surge in invalid, automated vulnerability reports. This pause specifically affects product vulnerabilities and does not impact supply chain reports or pending submissions. The company plans to re-evaluate and update the program in Q1 2027, encouraging researchers to focus on other reward programs like Patch Rewards.","Google pauses Open Source Software Vulnerability Reward Program due to automated reports.","Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions, saying a growing number of automated reports, most of them invalid, prompted the move. The pause was announced on X on October 1. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said. Only product vulnerabilities are covered by the pause. According to Google, it has no impact on the program’s supply chain reports or on any pending reports. “This change does not affect product vulnerabilities submitted before October 1, 2026,” the company noted in an update on the program’s page. Some product vulnerability reports may still be eligible elsewhere. “For some Google Cloud repos impacting Google Cloud products we may still accept reports covering product vulnerabilities through the Cloud VRP,” Google said.Advertisement. Scroll to continue reading. Google wants bug hunters to look for impact in its other vulnerability reward programs and submit their findings there. Researchers can also turn to its Patch Rewards Program, which offers rewards for proactively improving the security of open source projects. “We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” Google said. [ Read: Will AI Kill the Bug Bounty Industry? ] Introduced in 2022, the OSS VRP pays researchers for vulnerabilities found in Google’s open source projects. The OSS VRP pause follows changes Google made in May to its Chrome and Android reward programs, in response to the growing use of AI tools for vulnerability discovery. Standard Chrome payouts were reduced, as the company began favoring concise reports that provide concrete proof a bug exists. For Android, Google said it would prioritize vulnerability types that are harder for AI tools to find, and the top reward for a zero-click Pixel Titan M exploit with persistence went from $1 million to $1.5 million. In March, the Internet Bug Bounty (IBB) program run by HackerOne paused new submissions, saying the speed and volume of AI-assisted vulnerability discoveries had outpaced the open source community’s ability to deliver fixes. Related: Google Paid Out $17 Million in Bug Bounty Rewards in 2025 Related: Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers Related: OpenAI Launches Bug Bounty Program for Abuse and Safety Risks Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Crypto Scammers Hijack Microsoft’s Official X AccountAI Agents Aimed SQL Injection at US and Canadian Government SitesPolice Shut Down KillSec Ransomware, Identify Alleged Teen LeaderTreasury Blacklists Most-Wanted ATM Malware Developer and His NetworkGoogle Launches Gemini 4 Argon With Guardrail-Free Access for Vetted DefendersGoogle: AI Is Changing the Pace and Profile of Vulnerability DiscoveryGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit Latest News Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare FirmsExploitation Hits Rejetto HFS Vulnerability Discovered by AI Senate Passes Bipartisan Bill to Strengthen Healthcare CybersecurityAlleged ShinyHunters Leader Arrested in JordanExploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days EarlierTrump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Forcedoxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fgoogle-narrows-open-source-bug-bounty-amid-wave-of-invalid-automated-reports\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F06\u002Fvulnerability-software-bug.webp","2026-10-05T14:26:00+00:00","2026-10-05T16:01:10.56606+00:00",7,[18,21,24],{"name":19,"type":20},"Google Cloud","product",{"name":22,"type":23},"Google","vendor",{"name":25,"type":26},"AI","technology","02371804-cf6d-4449-98de-f1a2d4d9b266",{"id":27,"icon":29,"name":30,"slug":31},null,"Tools","tools",[33,35,40,45],{"category":34},{"id":27,"icon":29,"name":30,"slug":31},{"category":36},{"id":37,"icon":29,"name":38,"slug":39},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":46},{"id":47,"icon":29,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]