Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    October 5, 2026

    Google DeepMind Gives AI-Designed Proteins a Watermark

    October 5, 2026

    I tested Noble’s elite triple-driver wireless headphones and they offer some of the most hypnotic, spacious sound I’ve ever heard — if you can afford them

    October 5, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Tech Gadgets»Google benches open source bug bounty program following ‘significant rise’ in AI submissions
    Google benches open source bug bounty program following ‘significant rise’ in AI submissions
    Tech Gadgets

    Google benches open source bug bounty program following ‘significant rise’ in AI submissions

    The Tech GuyBy The Tech GuyOctober 5, 2026No Comments5 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement



    • Google paused OSS bug bounty submissions after a surge of AI-generated, invalid reports
    • AI boosts vulnerability discovery but often produces flawed, incomplete, or hallucinatory findings
    • Rising AI-driven bounty spam has also overwhelmed curl maintainers and Linux security reviewers

    Google has revealed it is pausing one of its bug bounty program and it’s all AI’s fault.

    Advertisement

    The company said its Open Source Software Vulnerability Rewards Program (OSS VRP) is being flooded with bogus and irrelevant submissions to the point where it was simply unmanageable.

    As a result, the company is pausing accepting all submissions until the end of the year, taking the time to reassess the process and come up with new solutions.

    Latest Videos FromTechRadar

    Bug hunting in the age of AI

    Generative Artificial Intelligence is supercharging defenders, discovering vulnerabilities at machine speed, making software better and more resilient against exploits and zero-day vulnerabilities.

    A few frontier models, including the famed Mythos and GPT-5.6-Cyber, have allowed companies to discover a hundred times more vulnerabilities in less time than ever before.


    You may like

    The best example is Microsoft’s Patch Tuesday. In March 2026, the company addressed 79 flaws in its products, and in April (around the time it started using Mythos) – almost double (167). From that day on, the number of patched bugs grew significantly month-over-month: 200 in June, 400 in August, and 966 in September. In just half a year, Microsoft started fixing more than ten times as many flaws.

    However, machines still cannot be trusted to discover and patch vulnerabilities entirely on their own. In early August, security researchers from 1Passwords Off-by-1 Labs set out to see just how good AI was at discovering and fixing flaws and found that half (49.3%) of the patches failed to fix at least one existing exploit path. A fifth (20.1%) fixed the original issue but changed application behavior, while 2.3% introduced new security issues. Funny enough, 2.2% failed to fix the vulnerability while also introducing additional exploit paths, as well.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Even among the patches that might be considered (26% of clean ones and 20.1% of those that changed app behavior), more than a third were fragile and not entirely addressing the underlying problem. 1Password concluded that missing context was the number one challenge, finding that when given proper background information, AI was able to produce significantly better results.

    Despite not being able to provide their AI with wider context, many security researchers still use AI for vulnerability discovery. Simple prompts, very little analysis, and even less human oversight, results in “discoveries” that are incorrect, unsubstantiated, and sometimes outright hallucinated. As a result, Google is (temporarily) stepping away from bounty submissions:

    “We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program,” Google said in a short tweet, published on October 1 2026.


    What to read next

    “Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027.”

    HackerOne and Linus Torvalds

    Google is not the first company whose bug bounty program choked to death on AI slop. In late January 2026, the developers of curl, the open source command-line tool and software library, announced killing their HackerOne bug bounty program due to being flooded with fake problems and vulnerabilities.

    In an advisory published on GitHub, it was said that the program is being sunsetted at the end of January, 2026.

    “Up until the end of January 2026 there was a curl bug bounty. It is no more,” the document reads. “The curl project no longer offers any rewards for reported bugs or vulnerabilities. We also do not aid security researchers to get such rewards for curl problems from other sources either.”

    A few months later, in May, lead maintainer of the Linux security mailing list, Linus Torvalds said it was “almost entirely unmanageable” due to researchers using AI to flood it with useless reports.

    “The continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools,” he said. “People spend all their time just forwarding things to the right people or saying “that was already fixed a week/month ago” and pointing to the public discussion”.


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Google logo on a black background next to text reading 'Click to follow TechRadar'

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    The Asus Googlebook 14 is sprinkled with hints of greatness

    October 5, 2026

    Here’s your first look at Google’s next fitness tracker, the Fitbit Edge

    October 5, 2026

    The Soulog Sense is an AI voice recorder with a personal context system that never misses a word

    October 5, 2026

    Plex just added 4 new free live TV channels to its streaming lineup

    October 4, 2026

    How to watch Patriots vs Bills: FREE Streams & TV Channels

    October 4, 2026

    This is when the Honor Magic9 series is landing in Europe

    October 4, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026392 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    October 5, 2026

    Google DeepMind Gives AI-Designed Proteins a Watermark

    October 5, 2026

    I tested Noble’s elite triple-driver wireless headphones and they offer some of the most hypnotic, spacious sound I’ve ever heard — if you can afford them

    October 5, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.