
Chip scarcity assaults auto industry amid the worsening Nexperia and DRAM crisis
The suspension went into effect on October 1 — the day of the announcement — and does not affect product vulnerabilities submitted before that date. Google said it may still accept reports covering product vulnerabilities through the Cloud VRP, “for some Google Cloud repos impacting Google Cloud products.” The suspension also does not affect OSS VRP supply chain reports. In a similar case, Linux ended support for older network drivers due to an influx of false AI-generated bug reports .
OSS VRP is a specialized Google security bounty program that incentivizes independent researchers to find and responsibly disclose security flaws across Google's open-source ecosystem. Under this program, product vulnerability submissions focus on code defects, logic flaws, or design bugs within Google's public repositories. This was usually painstaking, manual work requiring skill. However, the rise of large language models (LLMs) and automated AI bug-hunting scripts has nearly eliminated the cost and effort the task required, leading to an influx of low-effort, AI-generated bug reports.
Google engineers and open-source maintainers were reportedly being overwhelmed by thousands of these poorly written reports that claimed to find bugs but were actually completely invalid or unexploitable hallucinations. They ended up spending too much time manually validating code instead of actually fixing real, critical vulnerabilities. This is what has led to the suspension of the program.
Similar scenarios have been playing out across the industry. Earlier this month, Linux maintainers said they were “completely overwhelmed” by CVE finds after AI-powered bug hunters pushed the Linux kernel to a record 2,000 vulnerabilities per release. Intel also suspended its bug bounty program that paid up to $100,000 per flaw . The company did not officially confirm AI-generated reports as the reason for the move, but experts suspect this is the case.
Intel suspends bug bounty program that paid up to $100,000 per flaw
Key considerations
- Investor positioning can change fast
- Volatility remains possible near catalysts
- Macro rates and liquidity can dominate flows
Reference reading
- https://www.tomshardware.com/tech-industry/artificial-intelligence/SPONSORED_LINK_URL
- https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1#main
- https://www.tomshardware.com/membership
- Tencent scores 100,000 offshore AI chip deal with Oracle for $7 billion despite climbing prices
- California tech CEO arrested, faces up to 20 years in prison for smuggling $300 million in Nvidia AI servers to China
- How NVIDIA GPUs Help Accelerate OpenAI’s GPT-6 Astra Ultrafast
- From Training to Production, NVIDIA and CoreWeave Close the Loop on Agentic AI
- Buying used CPUs can expose users to existing bans from anti-cheat engines, and there's no way to check for violations before purchase
Informational only. No financial advice. Do your own research.