Google pauses open-source bug bounty as AI junk reports flood in

A security program built to reward careful researchers just shut its door on most new reports — and the reason is the same automation wave hitting everything else. Plus a wave of Western open weight launches is coming, and Stability AI's label backed pivot has product to show for it. Google has temporarily stopped accepting product vulnerability reports to its Open Source Software Vulnerability Rewards Program, blaming a surge of automated submissions that it says are overwhelmingly invalid.

Share
Google pauses open-source bug bounty as AI junk reports flood in

A security program built to reward careful researchers just shut its door on most new reports — and the reason is the same automation wave hitting everything else. Plus a wave of Western open-weight launches is coming, and Stability AI's label-backed pivot has product to show for it.

Google has temporarily stopped accepting product-vulnerability reports to its Open Source Software Vulnerability Rewards Program, blaming a surge of automated submissions that it says are overwhelmingly invalid. The company's official notice, posted October 1, says the pause covers only the product-vulnerability leg of the program — supply-chain reports keep flowing, submissions filed before October 1 are still honored, and Google promises an update in Q1 2027. Reporting on the freeze points to the wall of hallucinated, unexploitable vulnerability reports that AI tools have been pouring into bug-bounty channels all year; Google's own wording is more careful, citing "automated submissions, the vast majority of which are not valid" rather than naming AI directly. Either way the pattern is now hard to ignore: cURL ended its bounty in January over AI slop, HackerOne's Internet Bug Bounty paused in March, Apple capped submissions in August, and the Linux kernel is absorbing roughly 2,000 CVEs per release. The uncomfortable take: bug bounties were a trust market — pay for signal, filter noise in review — and cheap generation breaks that arithmetic, because the cost of a plausible-looking report has collapsed while the cost of triaging one hasn't. When the first major Google security program closes over machine-written junk, the burden shifts to platforms to verify the reporter before reading the report.


Reflection AI is reportedly about to ship its first open-weight model, part of a broader wave of Western open-weight releases this month. That's according to Axios, which says other Western players will follow — none of them named, and a Reflection spokesperson declined to comment, so treat the timing as an unnamed-sources scoop. The stakes are clear regardless: the model is expected to start behind the top U.S. labs but competitive with the best Chinese open-weight releases from DeepSeek and Qwen, which is exactly the gap Western labs have been trying to close since open weights became China's export to the world. Reflection has the runway for it — a reported $2 billion raise at an $8 billion valuation, billion-dollar-plus compute deals with Nebius and SpaceX, and prior reporting from The Information on its open-source push — but no model name, license, or benchmark has surfaced yet. What to watch: whether "this month" survives contact with the release calendar, and whether a second outlet confirms the rest of the lineup.


Sean Parker's Stability AI now looks less like a rescue story and more like a working bet on music professionals. The Information took a fresh look at the company's post-Emad Mostaque revival this weekend; the underlying proof is a $76 million Series B closed in late August, which brought all three major labels — Sony Music, Universal, Warner — onto the cap table alongside EA and AMD Ventures, a first for any AI company. Crucially it isn't only money: Stable Audio 3.0 shipped in June as a family of licensed-data music models that mostly ship open-weight, delivered as a plugin for working producers. Valuation and revenue remain undisclosed, so the honest read is that the pivot is real but still unaudited — and this is the labels' other answer to generative AI, beside the lawsuits: own a piece of the tool.

Is a bug bounty that closes to automated reports still a bug bounty — or does verification of the reporter become the product?

Read more

Change.org puts $100 million into rebuilding its platform with AI

Change.org puts $100 million into rebuilding its platform with AI

A quiet Sunday produced two stories about AI money and AI vocabulary — one nonprofit putting nine figures behind a rebuild, and a frontier lab owner rebranding to match Washington's new language. Change.org is investing $100 million of its own money to rebuild its core petitions platform around AI. The nonprofit — started venture backed, then moved into a nonprofit structure in 2021 when investors including Reid Hoffman and Sam Altman donated their shares — laid out the plan to Axios: the…

Anthropic's charity stock match hit $660 million pre-IPO

Anthropic's charity stock match hit $660 million pre-IPO

Anthropic is about to ask public market investors to value a company whose employees have been giving equity away at a scale that would be headline news for any listed firm. Anthropic's stock price match of employee charitable gifts exceeded $660 million in the six months through March, and The Information reports the pace is likely to reach billions a year once shares trade publicly — a cost that ultimately lands on shareholders.

Meta's Muse builds a page for everyone in your life

Meta's Muse builds a page for everyone in your life

A fresh round of uncomfortable evidence about what AI agents quietly keep on you — and the first concrete sign that AI generated slop is now breaking security programs, not just feeds. Meta's Muse builds a page for everyone in your life. Extracted system prompts for Meta's consumer agent show an instruction to compile "a page for every person in the user's life," with an hourly background job filling sections labeled Facts, History, The relationship, In common, Open threads, and Strengthening —…