AI slop submissions force Google to freeze its open-source bug bounty Google stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP) as of October 1, 2026, citing a significant rise in automated submissions that were largely invalid and AI-generated. The company's OSS VRP rules page states the pause follows the flood of automated reports that burdened the engineers and open source maintainers reviewing them. Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program OSS VRP , after a wave of invalid, AI-generated submissions swamped the engineers and open source maintainers who review them. The rules page for Google’s OSS VRP states that “as of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP.” “This pause is due to a significant rise in automated submissions, the vast majority … More https://www.helpnetsecurity.com/2026/10/05/google-ai-generated-vulnerability-reports-pause/ The post AI slop submissions force Google to freeze its open-source bug bounty https://www.helpnetsecurity.com/2026/10/05/google-ai-generated-vulnerability-reports-pause/ appeared first on Help Net Security https://www.helpnetsecurity.com .