Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Halts Bug Bounty for Open Source Amid Invalid Submissions

Google Halts Bug Bounty for Open Source Amid Invalid Submissions

Posted on October 6, 2026 By CWS

Google has temporarily suspended its bug bounty program for open-source software due to a spike in invalid automated submissions. Effective from October 1, 2026, researchers are no longer able to submit vulnerability reports for open-source projects such as Go, Angular, and Protocol Buffers for rewards. However, reports concerning supply chain security issues are still accepted, and those submitted before the cutoff date remain unaffected.

Reasons Behind the Suspension

The decision to pause the program was announced by Google on October 1 through a post on X, citing a significant increase in invalid submissions, many of which were automated. Although Google did not disclose specific figures or confirm the use of AI tools in these submissions, the rise in quantity and lack of quality prompted the temporary halt.

The Open Source Software Vulnerability Reward Program (OSS VRP) has been revised to reflect this change. While the program has not provided a specific timeline for resuming the acceptance of product vulnerability reports, Google has committed to an update by the first quarter of 2027.

Changes in Reward Structure

Prior to the suspension, the program categorized projects into four tiers based on sensitivity, with rewards ranging from $500 to $7,500 for flagship projects and $101 to $3,133.7 for important ones. These rewards have been removed from the OSS VRP rules, although supply chain compromises and other security issues, such as leaked credentials, still retain their reward structure.

Google’s public GitHub repository detailed these changes on September 30, a day before the announcement. The flagship repositories, which include projects like Go, Angular, and Protocol Buffers, and important repositories have specific reward structures for non-product vulnerabilities that remain unchanged.

Alternative Reporting Channels

In light of the suspension, Google has outlined alternative routes for reporting vulnerabilities. The Cloud Vulnerability Reward Program (Cloud VRP) may still accept certain reports affecting Google Cloud products. Additionally, the Patch Rewards Program offers compensation for security patches, provided they are accepted and remain in place for a month.

Researchers are encouraged to explore other Google reward programs that might cover the vulnerabilities they discover. Some projects, like Go, have specific channels for security reports, such as direct email to their security team, while others like Angular direct reports to Google’s Bug Hunters site.

Addressing Report Quality Concerns

The OSS VRP, launched in August 2022, had already implemented stricter proof requirements in March 2026 to enhance report quality. Concerns about AI-generated submissions, which sometimes included fabricated details, prompted these measures. Additionally, the Go project has updated its security policy to discourage unfiltered reports generated by large language models, highlighting the need for thorough review before submission.

As Google reassesses its program, the focus remains on maintaining the integrity and effectiveness of its bug bounty initiatives, ensuring that valid and impactful security vulnerabilities are identified and addressed.

The Hacker News Tags:AI-generated reports, automated reports, bug bounty, Google, Open Source, OSS VRP, Security, security flaws, supply chain security, Vulnerability

Post navigation

Previous Post: Google Enhances Android 17 Security with New Features
Next Post: Massive Data Breach Hits Denmark’s National Register

Related Posts

Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution The Hacker News
Microsoft Identifies 30 Domains Linked to MacSync Malware Microsoft Identifies 30 Domains Linked to MacSync Malware The Hacker News
China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems The Hacker News
Interlock Ransomware Exploits Cisco Flaw for Root Access Interlock Ransomware Exploits Cisco Flaw for Root Access The Hacker News
Cyber Attacks Hit Central Asia Using New Malware Tools Cyber Attacks Hit Central Asia Using New Malware Tools The Hacker News
Critical SGLang Vulnerability Allows Remote Code Execution Critical SGLang Vulnerability Allows Remote Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Atlassian Urges Quick Patch for Critical Security Flaws
  • Massive Data Breach Hits Denmark’s National Register
  • Google Halts Bug Bounty for Open Source Amid Invalid Submissions
  • Google Enhances Android 17 Security with New Features
  • AI Tools Enhance Social Engineering Defense

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Atlassian Urges Quick Patch for Critical Security Flaws
  • Massive Data Breach Hits Denmark’s National Register
  • Google Halts Bug Bounty for Open Source Amid Invalid Submissions
  • Google Enhances Android 17 Security with New Features
  • AI Tools Enhance Social Engineering Defense

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark