
David J. Rush admitted to wire fraud tied to a fake top secret government program.
Google has paused its Open Source Software Vulnerability Rewards Program after a significant rise in automated AI submissions, saying most were not valid.

Google has paused its Open Source Software Vulnerability Rewards Program, which rewarded researchers for finding vulnerabilities in the company’s open source software. The pause took effect October 1, and Google said it plans to provide an update in the first quarter of 2027.
The company attributed the move to a “significant rise” in automated submissions. Google said the vast majority of those submissions were not valid.
TechCrunch frames the pause as part of a broader strain on bug bounty programs caused by low-quality AI submissions. The article says cybersecurity experts had previously warned that AI slop and fake reports posed a serious risk to these programs.
According to the report, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. The takeaway for security teams is clear: submission volume is less useful when triage quality collapses.
Google encouraged participants to consider its other bug bounty programs while the open source program is paused. Researchers should verify findings carefully, avoid automated low-confidence reports, and focus on reproducible vulnerabilities.
For maintainers, the pause highlights the need for clearer submission standards and stronger filtering around automated reports. AI can speed up security work, but unverified output can also create expensive noise for teams already handling complex vulnerability queues.

David J. Rush admitted to wire fraud tied to a fake top secret government program.

The healthtech startup is scaling AI that flags hospital patients for closer review without making diagnoses.

Musubi’s PolicyLM-1.7B brings decision-model speed and flexibility to real-time content moderation.

The AI cloud startup is seeking up to $4B before a planned 2027 IPO.