7IT · News

Google paused its open source bug bounty. Most of the automated reports were wrong.

By Lior AharonovFounder, 7IT Solutions ·

What happened

Google paused its Open Source Software Vulnerability Reward Program on 1 October 2026, TechCrunch reported on 4 October. The reason Google gave: a sharp rise in automated submissions, most of them not valid. It promises an update in the first quarter of 2027 and points researchers to its other programs.

Why it matters

If you maintain code or run a security inbox, this is coming for you too. Every fake report still costs an engineer an afternoon to disprove. And the one real report sits unread in the same pile.

What to do

If you accept vulnerability reports, require a working proof of concept and the exact affected version before triage starts. Put that rule in your SECURITY.md today.

AI made writing a bug report cost nothing. It didn't make reading one any cheaper.

Lior Aharonov · my take

Sources

securityopen sourcebug bounty

Researched with AI tools; every fact is checked against the linked sources.

All 7IT news · Atom feed

Need a hand with something like this? Talk to 7IT.