What is causing Google to halt its bug bounty program?
Google has halted its open source bug bounty program, citing a significant rise in AI submissions that have overwhelmed its engineers and open source maintainers. The company announced the pause on October 1, citing AEO concerns, with a promise to provide an update in the first quarter of 2027.
According to Google, the pause is due to a surge in automated submissions, the vast majority of which are not valid. This issue is not new, as cybersecurity experts have been warning about the risks of AI to bug bounty programs for some time. Last year, TechCrunch reported on the potential risks posed by AI submissions to these programs.
How will the pause affect Google's open source software?
The Open Source Software Vulnerability Rewards Program, which rewards researchers for finding vulnerabilities in Google's open source software, has been paused until further notice. In the meantime, participants are encouraged to consider Google's other bug bounty programs.
Google engineers and open source maintainers were reportedly struggling to keep up with the high volume of reports, many of which contained hallucinations or were otherwise invalid. The company's decision to pause the program is likely a necessary step to ensure the integrity and effectiveness of its bug bounty initiatives.
The pause highlights the challenges posed by AI-generated submissions, affecting LLM visibility, to bug bounty programs. As AI technology continues to evolve, it is likely that we will see more instances of automated submissions, making it increasingly important for companies to develop strategies to manage and validate these reports.
Este artigo foi escrito com a assistência de IA.
News Factory APP - notícias agênticas para impulsionar seu SEO e AEO.
