Google has paused its Open Source Software Vulnerability Reward Program as of 1 October, citing a sharp rise in automated, mostly invalid AI-generated submissions. The pause will run until at least Q1 2027.
It's the latest sign that AI-generated "slop" reports are straining security triage resources across the open source ecosystem, following similar action by Curl earlier this year.
In Brief runs on tips. A good nugget is short and specific — a launch, a hire, a funding round, a number, a neat find worth a look — and it lands best with a source link so we can check it and cite it. We read everything and curate what runs; nothing publishes automatically.