CompaniesInvestorsPeople
Home
Loading

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

Get in Touch

  • Contact

  • Request a Demo

  • Request Data Updates

  • Add a Company

Research

  • Companies

  • Investors

  • People

aVenture

  • Download App

  • Pricing

Download the aVenture Research beta for iOS and iPadOSDownload aVenture Research on the Mac App Store

Resources

  • Documentation

  • Use Cases

  • CLI

  • MCP

  • Feature Requests

  • Sitemap

Member

Backed by

Ask AI about aVenture

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy · Terms of Service

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations

From Tom's Hardware

By Etiido Uko

October 3, 2026

Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations

Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations
  • Facebook
  • X
  • Whatsapp
  • Reddit
  • Pinterest
  • Flipboard
  • Email
Share this article
0
Join the conversation
Follow us
Add us as a preferred source on Google

Google has officially suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) — a bug bounty program — over an influx of invalid AI-driven reports. The company, in an official X post on October 1, encouraged participants to explore other VRP programs and committed to providing an update by the first quarter of 2027, while it reformats and works on this aspect of the program in the meantime.

Go deeper with TH Premium: AI shortages
  • AI data centers are swallowing the world's memory and storage supply
  • Demand for data center CPUs has surged, and AI agents are responsible
  • Chip scarcity assaults auto industry amid the worsening Nexperia and DRAM crisis
  • The custom AI ASIC state of play

The suspension went into effect on October 1 — the day of the announcement — and does not affect product vulnerabilities submitted before that date. Google said it may still accept reports covering product vulnerabilities through the Cloud VRP, “for some Google Cloud repos impacting Google Cloud products.” The suspension also does not affect OSS VRP supply chain reports. In a similar case, Linux ended support for older network drivers due to an influx of false AI-generated bug reports.

OSS VRP is a specialized Google security bounty program that incentivizes independent researchers to find and responsibly disclose security flaws across Google's open-source ecosystem. Under this program, product vulnerability submissions focus on code defects, logic flaws, or design bugs within Google's public repositories. This was usually painstaking, manual work requiring skill. However, the rise of large language models (LLMs) and automated AI bug-hunting scripts has nearly eliminated the cost and effort the task required, leading to an influx of low-effort, AI-generated bug reports.

Latest Videos FromTom's Hardware
Watch full video here:

Google engineers and open-source maintainers were reportedly being overwhelmed by thousands of these poorly written reports that claimed to find bugs but were actually completely invalid or unexploitable hallucinations. They ended up spending too much time manually validating code instead of actually fixing real, critical vulnerabilities. This is what has led to the suspension of the program.

Similar scenarios have been playing out across the industry. Earlier this month, Linux maintainers said they were “completely overwhelmed” by CVE finds after AI-powered bug hunters pushed the Linux kernel to a record 2,000 vulnerabilities per release. Intel also suspended its bug bounty program that paid up to $100,000 per flaw. The company did not officially confirm AI-generated reports as the reason for the move, but experts suspect this is the case.

You may like
  • Intel suspends bug bounty program that paid up to $100,000 per flaw
  • Linux kernel nears record 2,000 vulnerabilities per release as AI bug hunters scour 40 million lines of code
  • OpenAI and Anthropic are reportedly investigating tens of thousands of AI security incidents; OpenAI pauses testing after AI 'kill switch' fails to stop a rogue agent

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

Stay On the Cutting Edge: Get the Tom's Hardware Newsletter

Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.

Etiido Uko
News Contributor

Etiido Uko is a news contributor for Tom's Hardware covering the latest updates in big tech and the PC industry. He is a mechanical engineer and senior technical writer with over nine years of experience in documentation and reporting. He is deeply passionate about all things engineering and technology, and is an expert in gadgets, manufacturing, robotics, automotive, and aerospace.

Read more
Artificial Intelligence OpenAI and Anthropic are reportedly investigating tens of thousands of AI security incidents; OpenAI pauses testing after AI 'kill switch' fails to stop a rogue agent
Artificial Intelligence OpenAI, Google, and Anthropic absent from Nvidia-led Open Secure AI Alliance
Cybersecurity New hack exploits AI hallucinations to trick agents into running malicious code
Cybersecurity AI agents inadvertently leak 13,000+ internal screenshots from organizations
Artificial Intelligence Nvidia launches Open Agent Safety Platform to physically restrain rogue AI agents
Cybersecurity Hackers breach OpenAI using Claude tools, gaining access to employee accounts and the company's internal codebase
Latest in Artificial Intelligence
Artificial Intelligence ChatGPT-6 Astra plays World of Warcraft 'blind' and clears the orc starting zone in 40 minutes with no deaths
Artificial Intelligence California subpoenas OpenAI over rogue AI agents conducting hacking attacks
Artificial Intelligence AI agents use 5x more tokens than humans as cached prompts explode, headed for 10x
Artificial Intelligence California tech CEO arrested, faces up to 20 years in prison for smuggling $300 million in Nvidia AI servers to China
Artificial Intelligence PewDiePie unveils ‘uncensored’ Ajax AI model for home PCs
Artificial Intelligence AI's chipmaking frontier may face patent infringement hurdles as autonomous tools take over
Latest in News
Gaming PCs $5,245 prebuilt RTX 5090 PC's connectors melt after sitting boxed for a year
Cybersecurity Malicious VPN config files can let attackers run commands on Asus routers
Artificial Intelligence ChatGPT-6 Astra plays World of Warcraft 'blind' and clears the orc starting zone in 40 minutes with no deaths
CPUs AMD’s secret Zen 3 gaming CPU had 128MB of game-boosting L3 cache but never saw the light of day
Artificial Intelligence California subpoenas OpenAI over rogue AI agents conducting hacking attacks
Artificial Intelligence AI agents use 5x more tokens than humans as cached prompts explode, headed for 10x
No comments yet Comment from the forums

View original article on tomshardware.com

Most Recent

AI companies plot "day after" scenarios for public revolt

- The first example of significant real-world harm caused by unsafe AI would turn an already wary public further against the technology and its leaders …

Oct 9, 2026

Ramp Hits $60 Billion Valuation in $1.85 Billion Funding Round

Fintech startup Ramp has reached a roughly $60 billion valuation with its latest fundraising effort, according to people familiar with the matter.

Oct 9, 2026

Ultra raises $62 million for fast-growing ‘robots as a service’ business, announces tie-up with AI research firm Physical Intelligence

Finance editor Jeff John Roberts here. The explosive growth of the robotics industry in recent years is reflected in new technology feats …

Oct 9, 2026

Tesla renames 'Full Self-Driving' to 'Tesla Assisted Driving' in Europe

The name change is enough for Germany's transport minister to start advocating for Europe-wide adoption of the driver assistance software.

Oct 9, 2026

Similar Posts

The Rise and Fall of Agent Civilizations

The whole OpenAI/Hugging Face story in plain English

Aug 29, 2026

OpenAI and the Wiki Incident

I did not expect to be back here so soon with more OpenAI agent swarm coverage.

Sep 6, 2026

An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang

TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.

Sep 18, 2026

Google finds vulnerability disclosures doubled as AI changes which flaws get discovered

A new report out today from Google LLC’s Google Threat Intelligence Group finds that monthly software vulnerability disclosures doubled between January and August. Not surprisingly, artificial intelligence is changing which flaws get discovered as well, and GTIG said half of those turned up by AI ag

Sep 30, 2026