AI slop got so bad Google paused a hacker reward program

stache.tech

AI slop is no longer only filling your feed with fake movie trailers and six-fingered people.

Now it is annoying cybersecurity researchers too.

Google has temporarily paused part of its Open Source Software Vulnerability Rewards Program, after receiving a growing number of automated vulnerability reports that turned out to be invalid.

The programme normally rewards security researchers for finding genuine vulnerabilities in open-source software connected to Google.

That system works when someone actually finds a bug.

The problem is that generative AI has made it extremely easy to produce reports that look technical without necessarily identifying a real security problem.

Google says it saw a significant rise in automated submissions, with many failing to meet the programme’s standards.

For open-source maintainers, that creates another job: reading through convincing-looking reports only to discover that the supposed vulnerability does not actually exist.

There is already a name for this phenomenon in developer circles: AI slop.

Google has now paused the product-reporting portion of the programme while it works out how to handle the flood, with another update expected in early 2027.

Importantly, Google has not shut down all of its bug bounty programmes. The change concerns a specific part of its open-source vulnerability rewards system.

Still, the situation says something pretty funny about where we are with AI.

We spent years worrying that AI would become good enough to find security vulnerabilities before humans.

Instead, one of the immediate problems is AI confidently reporting vulnerabilities that aren’t there.

Even hackers are getting spam now.

Les articles Premium et les archives LNT en accès illimité
 et sans publicité