Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-05 · updated: 2026-10-05 · tags: [incident, global] · confidence: high · severity: medium · affected_sectors: [global] · au_impact: true

Google paused its Open Source Software Vulnerability Rewards Program as of 1 October, citing "a significant rise in automated submissions, the vast majority of which are not valid", with an update promised in the first quarter of 2027. The freeze — the concrete confirmation of warnings last year that AI slop posed a serious risk to bug-bounty economics — means Google's engineers and open-source maintainers were overwhelmed by invalid or hallucinated reports, and the company has redirected participants to its other programs while the freeze runs. The implications run wider than one vendor: if a major program cannot absorb the volume of machine-generated noise, the model of unpaid triage underpinning open-source vulnerability disclosure is degrading at exactly the moment that volume is accelerating. Australian and New Zealand organisations relying on Google's open-source components gain nothing in safety from the pause — and the backlog of genuinely unfunded vulnerabilities underneath the noise is the real exposure.

Attribute Detail
Sector Global (Macro)
Date 2026-10-05
Source TechCrunch
Reliability Tier 3