Google pauses OSS bug bounty program due to AI submissions

Google has halted submissions for its bug bounty program due to an increase in invalid AI-generated reports. The company will reassess the process until the end of the year.
Google has announced the suspension of submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) following a significant rise in reports generated by artificial intelligence. The company stated that the influx of erroneous, incomplete, or irrelevant reports has become unmanageable, prompting this decision.
Why it matters
This change is important as it highlights a growing challenge at the intersection of artificial intelligence and software security. While AI can expedite the discovery of vulnerabilities, it has also enabled the generation of reports that are not useful or are outright false, diverting valuable resources from security teams.
What we know
Google has confirmed that submissions will be paused until the end of the year, during which time the company plans to reassess the process and seek solutions to better filter valid reports from invalid ones. This step is crucial to maintaining the integrity of the program and ensuring that bug hunting efforts are effective.
What remains unclear
It is still unclear how Google plans to tackle the issue of AI-generated reports and what specific measures will be implemented to improve the submission and review process in the future. Open source users and developers are awaiting further information on how the program will be restructured.
Read at the original source:
TechRadar →Related news
SecurityShould you stop saving passwords in Chrome?
A user shares their experience on saving passwords in Chrome and the concerns that come with it.
SecurityBitdefender launches AI Guardian, a new security tool for Mac
Bitdefender introduces AI Guardian, a free tool that protects Mac users from potential attacks on AI models. This application checks the actions of autonomous software agents before they are executed.
SecurityRise in banking scams targeting mobile devices
A new report reveals a 35% increase in banking scams targeting mobile users. This shift suggests that scammers are adapting their tactics to take advantage of mobile accessibility for transactions.