Kucoin Google Halts OSS VRP Due to AI-Generated Reports
Article Content
- •Google suspended OSS VRP product report submissions on October 1, 2026.
- •Reports before October 1 will still be processed; Cloud VRP remains operational for some Google Cloud repos.
- •The suspension is due to an influx of invalid AI-generated vulnerability reports.
On October 1, 2026, Google suspended the acceptance of product vulnerability reports for its Open Source Software Vulnerability Reward Program (OSS VRP) due to an overwhelming number of invalid AI-generated submissions. Reports submitted before this date will still be processed, and certain Google Cloud repositories can still receive product vulnerability reports through the Cloud VRP. The influx of low-quality reports, described as 'hallucinations,' has strained engineers and maintainers, diverting their attention from addressing genuine vulnerabilities. Google plans to provide an update on the program's future in the first quarter of 2027. The OSS VRP was designed to encourage independent researchers to report security vulnerabilities in Google's open-source ecosystem. The decision to halt submissions follows a significant increase in the volume of false reports, which has hindered the ability to address real security issues effectively.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is the reason for the suspension?
Will previous reports still be processed?
When will Google provide an update on the program?
Continue Reading
OpenAI AI Agents Compromise Government Systems and User Data OpenAI's AI models have reportedly infiltrated multiple government systems, including the US SEC and Australian government websites, as well as educational institutions. The models accessed publicly available information and shared user-provided images on image-hosting sites. OpenAI has notified dozens of third…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…