Google freezes open-source bug-bounty reports over AI-slop flood

Supply-chain and Cloud reports still pay; curl did the same in July. Plus: Copilot code review gets an API and Tavus ships real-time video avatars.

Nowline OCT 5 2:00 AM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • Google halts product bug reports to its OSS bounty

    Effective Oct 1, Google stopped accepting product-vulnerability reports to its Open Source Software VRP, saying engineers were drowning in AI-hallucinated “bugs” that turned out to be non-security coding errors. Supply-chain submissions and the Cloud VRP stay open, pre-Oct-1 reports are still being processed, and Google says it’ll share the program’s future by Q1 2027.

  • The AI-slop reckoning reaches security triage

    This is the curl problem gone mainstream: curl shut its HackerOne bounty in July over fake AI-written CVEs, and now a hyperscaler has pulled the same lever. If you file vulnerabilities, expect AI-generated reports to get deprioritized or auto-rejected across more programs—lead with a reproducible PoC, not an LLM summary, or watch your signal get buried with the noise.

  • GitHub Copilot code review gets a real API

    You can now trigger Copilot code reviews through GitHub’s REST and GraphQL APIs and set the review effort per request—so automated review can live in your own CI, scripts, and internal tools instead of only the PR UI. “Balanced” is now the default effort level; it’s GA on Copilot Pro, Pro+, Max, Business, and Enterprise.

  • Tavus Griffin-Lite: build real-time AI video avatars

    Tavus’s new Griffin-Lite is a full-duplex video-to-video interaction model—it watches and responds on camera in real time, and reportedly clears 48% of video Turing tests. If you’re building face-to-face agents, tutors, or support bots, it’s a drop-in conversational-video layer rather than a text bot with a talking-head bolted on.