AI

Google halts open-source bug bounty program amid AI spam surge

Google has temporarily suspended submissions to its Open Source Software Vulnerability Rewards Program following a massive flood of AI-generated bug reports.

·1 min read
Google halts open-source bug bounty program amid AI spam surge

Tech giant Google has announced a temporary suspension of new submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP). The drastic measure was taken due to an overwhelming surge of low-quality and fake reports generated automatically by artificial intelligence tools.

According to BleepingComputer, the flood of incoming submissions has severely impacted the ability of security teams to review reports and identify genuine, critical vulnerabilities. Consequently, the company had to hit pause on the program to reorganize and address the spam issue.

The widespread accessibility of generative AI tools has made it easy for individuals to mass-produce vulnerability claims in hopes of securing bounty rewards. This has placed an unprecedented burden on security analysts who now have to sift through mountains of AI-generated noise rather than focusing on real threats.

This incident highlights the growing challenges that major technology companies face in the era of accessible artificial intelligence. For developers and cybersecurity professionals worldwide, it serves as a reminder of how automated tools are altering the landscape of vulnerability disclosure programs.

Google security teams are currently working on implementing better filters and safeguards to mitigate the influx of automated spam before reopening the program. Further updates regarding the resumption of submissions are expected in the future.

#BleepingComputer

Related articles