Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
Google Freezes Open Source Bug Bounty Program After AI Generated Junk Reports Overwhelm Engineers

Google pulled the plug on part of its open source bug bounty program because AI chatbots keep making up vulnerabilities that don't exist.
As of October 1, 2026, Google stopped accepting new product vulnerability submissions to its Open Source Software Vulnerability Reward Program, known as OSS VRP. The company announced it in a post on X and on the program's website, blaming what it called "a significant rise in automated submissions, the vast majority of which are not valid."
Google did not provide hard numbers on how many reports flooded in or how many got tossed, according to AI Breaking Wire. But the pattern across the company's statements is clear: engineers and open source maintainers were drowning in AI-generated garbage dressed up as serious security findings.
What the pause actually covers
This isn't a full shutdown. Google and the Times of India both laid out the specifics. Reports filed before October 1 are unaffected. Supply chain disclosures under OSS VRP remain open. And some product vulnerability reports tied to Google Cloud repositories can still go through the separate Google Cloud VRP.
Google is pointing researchers toward its other active bounty programs, including the Patch Rewards Program, while it reworks the submission process. The company says it will give a progress update in the first quarter of 2027, per Tom's Hardware and TechCrunch.
The AI slop problem
Large language models can generate a bug report that reads like it was written by a skilled researcher, complete with technical jargon and a plausible-sounding exploit chain. Tom's Hardware reported that many of these submissions were "completely invalid or unexploitable hallucinations" — the AI essentially invented a bug that was never there.
That used to be expensive to fake. Finding and documenting a real vulnerability took skill and hours of manual work. Now anyone with a chatbot can spit out dozens of fake reports in minutes, and Google's own engineers have to manually triage every single one to confirm whether it's real. Crypto Briefing noted this is precisely the bottleneck: bug bounty programs run on human review, and a human has to read, try to reproduce, and judge each submission.
This isn't Google's first move here either. Crypto Briefing reported the company already tightened its VRP evidence requirements back in March 2026 and made changes to its Android and Chrome reward programs during the year. The October 1 freeze is described as the most aggressive step Google has taken so far.
Google isn't alone
The problem is industry-wide. Tom's Hardware and TechManNews both reported that Linux maintainers said they were "completely overwhelmed" after AI-powered bug hunters pushed the kernel to a record 2,000 vulnerabilities flagged per release, and that Linux ended support for some older network drivers specifically because of an influx of false AI-generated bug reports.
Intel also suspended its own bug bounty program, which had paid out up to $100,000 per flaw. Intel has not officially confirmed AI-generated reports as the reason, and no source here establishes that link as fact, only that experts suspect it. That distinction matters: one is a confirmed cause, the other is speculation Tom's Hardware and TechManNews both flagged as unconfirmed.
Crypto Briefing also reported that the Internet Bug Bounty program has run into the same wall, as has the broader open source ecosystem, where small volunteer teams have zero spare capacity to debunk a hallucinated vulnerability every few hours.
The fair pushback
AI boosters have a real point: this is a tooling and incentive problem, not proof AI is useless for security work. Automated scanning has genuinely found real vulnerabilities in the past, and a flood of low-quality submissions doesn't mean every AI-assisted report is worthless. The friction Google is describing could be read as early-stage growing pains in a system that hasn't yet built the filters to separate real findings from hallucinated ones.
By Google's own account, the vast majority of the recent submissions were not valid, and the volume was high enough to force a freeze rather than a tweak. Legitimate researchers who actually find real flaws in Google's open source code now have to wait for a 2027 update, or redirect their work to Google's other VRP tracks in the meantime.
What happens next depends on whether Google can build a triage system, likely automated itself, that filters hallucinated reports before they reach a human. Until that update lands in the first quarter of 2027, the open source bounty door stays shut.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.