Google因AI提交显著增加暂停开源漏洞赏金计划
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google已暂停Open Source Software Vulnerability Rewards Program,原因是自动化提交显著增加且绝大多数无效。该计划自10月1日起暂停,公司承诺在2027年第一季度提供更新;工程师和开源维护者被无效或含幻觉的报告淹没。在此期间,参与者被鼓励考虑Google的其他漏洞赏金计划。
Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year.
Last year, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs. Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software.
In posts on X and the program website, Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. According to Tom’s Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.
In the meantime, participants are encouraged to consider Google’s other bug bounty programs.
来源:TechCrunch · AI · techcrunch.com