Security

Google pauses OSS bug bounty program due to AI submissions

1 min readSource: TechRadar
Google pauses OSS bug bounty program due to AI submissions

Google has halted submissions for its bug bounty program due to an increase in invalid AI-generated reports. The company will reassess the process until the end of the year.

Google has announced the suspension of submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) following a significant rise in reports generated by artificial intelligence. The company stated that the influx of erroneous, incomplete, or irrelevant reports has become unmanageable, prompting this decision.

Why it matters

This change is important as it highlights a growing challenge at the intersection of artificial intelligence and software security. While AI can expedite the discovery of vulnerabilities, it has also enabled the generation of reports that are not useful or are outright false, diverting valuable resources from security teams.

What we know

Google has confirmed that submissions will be paused until the end of the year, during which time the company plans to reassess the process and seek solutions to better filter valid reports from invalid ones. This step is crucial to maintaining the integrity of the program and ensuring that bug hunting efforts are effective.

What remains unclear

It is still unclear how Google plans to tackle the issue of AI-generated reports and what specific measures will be implemented to improve the submission and review process in the future. Open source users and developers are awaiting further information on how the program will be restructured.

Share:

Read at the original source:

TechRadar →
#google#bug-bounty#ai#seguridad#open-source

Related news