Google Halts OSS Product Bug Bounty Rewards as AI-Generated Invalid Reports Flood In
RedSide Security October 07, 2026 Cybersecurity 17 views
Google has stopped accepting product vulnerability reports for its open-source software through its bug bounty program, citing a surge in invalid automated submissions. Supply chain reports remain in scope, and pre-October 1 filings will still be processed.