Google paused its Open Source Software Vulnerability Rewards Program as of 1 October, citing "a significant rise in automated submissions, the vast majority of which are not valid", with an update promised in the first quarter of 2027. The freeze — the concrete confirmation of warnings last year that AI slop posed a serious risk to bug-bounty economics — means Google's engineers and open-source maintainers were overwhelmed by invalid or hallucinated reports, and the company has redirected participants to its other programs while the freeze runs. The implications run wider than one vendor: if a major program cannot absorb the volume of machine-generated noise, the model of unpaid triage underpinning open-source vulnerability disclosure is degrading at exactly the moment that volume is accelerating. Australian and New Zealand organisations relying on Google's open-source components gain nothing in safety from the pause — and the backlog of genuinely unfunded vulnerabilities underneath the noise is the real exposure.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-05 |
| Source | TechCrunch |
| Reliability | Tier 3 |