Skip to content

The news behind the software that runs companies, explained for everyone.

Security

Google paused its open-source bug bounty after an AI report flood. Most were invalid.

Google stopped accepting reports of product flaws for its Open Source Software Vulnerability Rewards Program on 1 October, TechCrunch reported on Sunday.

ERP LEADERS news desk · · First reported by TechCrunch · Edition no. 28

"This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company said. It promised an update in the first quarter of 2027.

The programme paid outside researchers for finding flaws in Google's open-source code. Tom's Hardware reported that Google engineers and the people who look after open-source projects were overwhelmed by thousands of poorly written reports. Many were invalid or contained AI-generated false information. Reports about the tools and packages used to build software are still accepted.

Invalid submissions earn no reward. Reviewers still have to check each one before they can close it. Google has not said how many submissions arrived. The pause takes that workload off its engineers and maintainers until the promised update in early 2027.

Has AI-written noise reached your support requests or audit findings yet?

Image: AI-generated.

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story

Our file on Google

  1. 7 OctFiled later

    Google signed for 890 megawatts from 11 old nuclear plants. Nobody builds new ones.

  2. 1 Oct

    Google pays about 100 publishers when their pages shape AI answers.

  3. 1 Oct

    Google's new AI guessed wrong on 15% of questions it couldn't answer. OpenAI's 51%.

  4. 1 Oct

    Trump ordered federal agencies to rename AI. The new word is Super Intelligence.

  5. 30 Sept

    Google challenged two EU orders that help rival AI in court.

All 23 Google stories

For your next steering committee

Questions for your own programme. They are not findings about any company in this story.

  1. 1Ask which design decisions in your programme would be expensive to reverse, and when each was last reviewed.
  2. 2Ask which expected benefits change if the implementation approach changes.
  3. 3Ask who owns a decision to change course, and where it would be recorded.

Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01

Founding reader view is on in this browser. It is a reading view, not secure access. Print the working sheet

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Subscribe