{"data":{"id":"d9580e01-4527-442b-a2c1-83b5d4178d8f","title":"Google’s bug bounty pause highlights growing AI vulnerability triage challenge","summary":"Google has temporarily stopped accepting certain bug bounty submissions after a surge of largely invalid AI-generated reports. The company had earlier tightened its open-source vulnerability program rules, asking for stronger evidence such as reproducible results or accepted patches, and stopped rewarding certain lower-tier product vulnerability reports. Commentators argue that AI can make poorly substantiated reports cheap to produce, so receiving teams must still verify whether the affected code exists and the attack path is reachable.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"https://www.csoonline.com/article/4231109/googles-bug-bounty-pause-highlights-growing-ai-vulnerability-triage-challenge.html","publishedAt":"2026-10-06T10:10:21.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["Google","Anthropic"],"affectedVendorsRaw":["Google bug bounty program","Anthropic Mythos vulnerability-hunting model"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-06T10:10:21.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}