InfoNews
Google’s bug bounty pause highlights growing AI vulnerability triage challenge
- Published
- Record updated
Summary
Google has temporarily stopped accepting certain bug bounty submissions after a surge of largely invalid AI-generated reports. The company had earlier tightened its open-source vulnerability program rules, asking for stronger evidence such as reproducible results or accepted patches, and stopped rewarding certain lower-tier product vulnerability reports. Commentators argue that AI can make poorly substantiated reports cheap to produce, so receiving teams must still verify whether the affected code exists and the attack path is reachable.
Related items
- InfoAnthropic’s AI gave Philadelphia police a fake tip about an unsolved homicideSame vendor · The Verge (AI)
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic Launches Free AI Vulnerability Scanner for Open-Source ProjectsSame vendor · The Hacker News
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review