Open Source
Organizations running bug bounty and vulnerability disclosure programs must now budget for AI-generated noise filtering and governance controls; this signals that relying on community-driven security models requires new policies and moderation infrastructure to remain viable at scale.
Google has frozen its open source bug bounty program after experiencing a significant surge in AI-generated submissions, with many being low-quality or irrelevant. The move reflects a broader challenge facing bug bounty platforms as generative AI tools make it easier for participants to flood programs with automated, low-effort reports.
Read the full article at TechCrunch
CoFabrix summarises and comments on this story. The original reporting belongs to TechCrunch.
Find out where your organization stands -- and what to do about it.