News · curated 5 Oct 2026

Google halts open-source bug bounty program amid AI spam surge

Coverage timeline

5 Oct 2026bleepingcomputer.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Google halting its OSS bug bounty shows how LLM-generated 'slop' vulnerability reports are overwhelming disclosure channels, degrading signal-to-noise for defenders and maintainers across the open-source ecosystem.

Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded with AI-generated reports, the vast majority of which are invalid. The company says it will reformat the program to address automated submissions and provide an update in Q1 2027, while supply-chain reports and the Patch Rewards Program remain unaffected.