What’s trending in AI on 4 October 2026: the system the software world uses to find and fix security holes is buckling under AI, and it is failing in two directions at once. On 1 October Google stopped accepting product vulnerability reports in its Open Source Software Vulnerability Reward Program (OSS VRP) after maintainers were buried in AI-written reports describing bugs that do not exist. In the same week, a very real bug found by Anthropic’s Mythos model in the Rejetto HTTP File Server (HFS) was being exploited the day after researchers published how it worked. And on 2 October the COSMIC desktop project from System76 banned AI-generated content from pull requests altogether. Fake findings are drowning the people who fix software, while real AI findings are reaching attackers faster than ever. This guide explains what happened, why the bug bounty model is breaking, what it means for any business that runs on open source, and a scored triage checklist you can use on Monday morning.
Key takeaways
- Google paused OSS VRP product submissions on 1 October 2026 because of thousands of invalid, AI-generated reports. Supply-chain reports still count, reports filed before 1 October stay valid, and Google promises an update by Q1 2027.
- It is part of a pattern: HackerOne’s Internet Bug Bounty paused in March, Intel quietly ended paid rewards in September, and Linux kernel CVEs have climbed toward about 2,000 per release.
- Real AI findings are dangerous too: CVE-2026-61500 in Rejetto HFS (CVSS 9.8), found with Mythos, lets an attacker forge an admin session and run code. Exploitation was detected the day after the detailed write-up.
- The fix had existed for weeks: the CVE record dates from July and HFS 3.2.1 closes the hole. The public explanation, not the patch, started the clock.
- The bottleneck is now remediation, not discovery. Maintainers have the same hours; the queue does not.
- For your business: rank vulnerabilities by evidence of exploitation and by exposure, watch your open-source dependencies for slower fixes, and never let staff or vendors submit unverified AI bug reports in your name.
1. What happened this week
Google froze part of its open-source bounty. Google’s OSS VRP pays researchers who find security flaws in open-source projects Google maintains, from Go and Angular to Bazel and many smaller libraries. As reported by Tom’s Hardware on 3 October, Google ended product vulnerability submissions to the program from 1 October 2026. The reason is volume and quality: Google said its engineers were “overwhelmed by thousands of these poorly written reports”, many of them describing hallucinated flaws. Each one still had to be read, reproduced and rejected by a person, which meant less time for real fixes. Reports filed before the cut-off remain valid, OSS VRP supply-chain reports continue, some Google Cloud repositories still accept reports through the Cloud VRP, and Google says it will share an update on a reworked program by the first quarter of 2027. Earlier this year Google had already tightened the rules by asking for stronger evidence, such as an OSS-Fuzz reproduction or a merged patch, for some reports.
A Mythos-found flaw went from write-up to attack in about a day. On Wednesday 30 September, Zach Hanley of the AI penetration-testing company Horizon3.ai published how his team used Anthropic’s restricted Mythos model to find CVE-2026-61500 in Rejetto HFS, a popular, lightweight file-sharing web server. HFS 3.x signed its session cookies with a key built from JavaScript’s Math.random(), which is not designed for security. Separately, the app leaked raw outputs of that same random generator through its login responses. Mythos connected the two facts, worked out that a constraint solver could rebuild the generator’s internal state from the leaked values, and produced a working exploit that forges an administrator session and leads to remote code execution. The flaw is scored 9.8 and affects HFS 3.0.0 through 3.2.0; version 3.2.1 fixes it. According to The Register, VulnCheck’s Patrick Garrity reported exploitation by Thursday evening, with an actor in China targeting real vulnerable hosts in the US and more activity from two US addresses that appeared to be proxies.
An open-source desktop banned AI-written contributions. On 2 October the COSMIC desktop environment, built by System76, changed its contribution rules so that pull requests may not contain any LLM-generated material: no AI-written code, comments or descriptions. Contributors must confirm this and also state that they understand, have tested and can defend their changes. System76’s Jeremy Soller tied the decision to the extra review work caused by first-time contributors submitting AI-generated pull requests that were rarely good enough to merge. Previously the team had asked for AI use to be disclosed; the new rule replaces disclosure with an outright ban.
2. The paradox: AI is finding real bugs and fake ones
It is tempting to read these stories as “AI bug reports are junk” or “AI is a super-hacker”. Both are true, for different users. Frontier models used by skilled researchers inside a careful process are finding serious, long-hidden flaws. The Rejetto bug is a good example: two weaknesses that each look minor, chained through a piece of maths most human reviewers would not attempt. Earlier this year Claude Opus 4.6 was reported to have found 22 Firefox vulnerabilities in two weeks, 14 of them rated high severity. We covered how these capabilities are being rationed in the best cyber models going behind a velvet rope, and how an open-weight model nearly matched Mythos in our GLM-5.3 analysis.
Meanwhile, anyone with a chatbot can paste in a code repository, ask for vulnerabilities and file whatever comes back for a chance at a reward. Generating a convincing report costs seconds. Proving it false can cost a maintainer an hour or more. That asymmetry is the whole problem, and it is the same one we described in the proof-of-human problem: when producing plausible content is free, every human checkpoint gets flooded.
| Trait | Expert-driven AI finding | Low-effort AI “slop” report |
|---|---|---|
| Who is behind it | A researcher or vetted team using a strong model as one tool | Someone pasting code into a chatbot and filing the output |
| Proof | Working proof-of-concept, clear reproduction steps | Generic description, no reproduction, code that does not exist |
| Cost to maintainer | Time to fix a real bug | Time to disprove a bug that was never there |
| Example this week | CVE-2026-61500 in Rejetto HFS, found with Mythos | The reports that pushed Google to pause OSS VRP product submissions |
| Risk to you | Fast weaponization once details go public | Slower fixes for everyone because maintainers are swamped |
3. Why the bug bounty model is breaking
Bug bounties were built on a simple trade: finding bugs is hard and scarce, so pay people who do it, and the fixing will take care of itself. AI has flipped both halves. Discovery is now cheap and plentiful, while fixing still depends on a small number of maintainers, many of them volunteers. Google’s pause is the most prominent sign this year, but it is not the first.
- HackerOne’s Internet Bug Bounty, which has funded open-source fixes since 2012 and paid out more than $1.5 million, stopped taking new submissions on 27 March 2026. HackerOne said AI-powered research had changed the balance between discovery and remediation in open source.
- The Linux Foundation received $12.5 million in security funding in the spring from Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft and OpenAI. Kernel maintainer Greg Kroah-Hartman warned that grants alone would not solve the load AI tools put on open-source security teams.
- The Linux kernel is approaching about 2,000 CVEs per release, up from roughly 500 in the 6.x era, even though the code base has not grown at anything like that rate. Linus Torvalds has called the volume of AI reports “almost entirely unmanageable”.
- Intel replaced its paid bug bounty, which offered $500 to $100,000 per flaw, with an unpaid disclosure program on Intigriti around 19 September. Intel gave no public reason; the link to AI-assisted reporting is speculation by observers, not Intel’s stated rationale.
- curl, the widely used command-line networking tool, also suspended bounty submissions earlier after a stream of low-quality AI reports.
Some of this growth is healthy. Old bugs that were always there are finally being found and named, and the kernel’s decision in 2024 to issue its own CVEs means more issues are disclosed than before. But the numbers create a new problem for everyone downstream: when nearly everything is labelled important, nothing is. Security Boulevard cites analysis from Zest Security showing that among scanner findings rated high or critical, fewer than one in four hundred, under 0.25%, had evidence of real-world exploitation.
4. The Rejetto lesson: the write-up is the starting gun
The most useful detail in the HFS story is easy to skip. The CVE record for CVE-2026-61500 dates from 13 July 2026, and the fixed version is 3.2.1. For about eleven weeks, anyone who upgraded was safe and nobody appears to have been attacking it. What changed on 30 September was not the bug; it was the publication of a clear, step-by-step explanation of how to exploit it. Within roughly a day, attackers were using it against real servers.
Two more details matter. First, the exploit prediction score listed for this CVE was low, at about 0.75% over 30 days, which shows why probability scores should guide, not replace, judgement when a detailed write-up appears. Second, HFS is the kind of tool that often lives outside formal IT: a quick file-sharing server someone set up on a spare machine years ago. Those are exactly the systems that miss patches. Microsoft made the same point about speed in the report we covered in the 24-hour window; the HFS case shows the trigger is often public detail rather than the patch release itself.
5. What it means for your business
Most companies never file a bug report, so it is easy to think this is a problem for open-source projects only. It is not. Nearly every business runs on open-source code, inside its website, its cloud services, its laptops and the SaaS tools it pays for. When maintainers are swamped, three things happen to you.
- Fixes may slow down. Time spent disproving fake reports is time not spent fixing real ones, and some programs that funded that work are paused. Expect longer gaps between disclosure and patch in smaller projects.
- Your vulnerability queue gets longer and noisier. More CVEs means more scanner alerts. If your team sorts by CVSS score alone, it will spend the week on findings that will never be exploited and may miss the one that is.
- The window after public details shrinks. As the HFS case shows, a readable write-up can be turned into attacks within a day, and AI helps attackers read write-ups faster too.
There is also a reputational angle. Staff, contractors or security vendors who run AI scanners and paste the output into other people’s bug trackers under your company’s name can damage relationships with the projects you depend on. Treat that like any other shadow AI risk and set a rule before it happens. If you build software that bundles open-source components, the supply-chain view in our GPT-6 Astra supply-chain analysis is a useful companion.
6. The vulnerability flood scorecard
Instead of another to-do list, score your team. Give yourself the points for each statement that is true today. Anything under 12 means the AI-driven flood of disclosures is more likely to hurt you than help you.
| Statement | Points | If not, first move |
|---|---|---|
| We have a current software inventory that includes “unofficial” servers such as file-sharing tools and test boxes. | 3 | Run an external attack-surface scan and ask teams what they set up themselves. |
| Our patch queue is sorted by known exploitation first (for example CISA’s KEV list or vendor alerts), not CVSS alone. | 3 | Add a KEV feed to your scanner and make it the top sort key. |
| Internet-facing systems with a public exploit write-up are patched or isolated within 48 hours. | 3 | Agree an emergency path with change control in advance. |
| Someone watches security advisories for our top 20 open-source dependencies. | 2 | Turn on dependency alerts in your code host or SCA tool. |
| We know which critical dependencies rely on one or two volunteer maintainers. | 2 | Check project health and consider sponsoring or replacing fragile ones. |
| We have a written rule that AI-found vulnerabilities must be reproduced by a human before anyone reports them externally. | 2 | Add one line to your AI acceptable-use policy. |
| Our own vulnerability disclosure page asks for a proof-of-concept and says how AI-assisted reports are handled. | 2 | Update your security.txt and disclosure page. |
| Our security vendors tell us how they filter AI-generated noise from their findings. | 1 | Ask at the next review. |
| We have rehearsed what we would do if a key open-source component went unpatched for 30 days. | 1 | Write a one-page compensating-controls plan (WAF rule, isolation, feature off). |
For the patch-speed rows, our guide to stricter patch deadlines covers how regulators and standards now set the clock, and yesterday’s AI control plane alert shows the kind of system that should sit at the top of the list.
7. If you run a bug bounty or disclosure program
Software vendors, SaaS providers and any company with a public security page are now on the receiving end of the same flood. The responses that are emerging share a few traits.
- Require proof. Like Google’s earlier move toward reproductions and merged patches, ask for a working proof-of-concept or exact reproduction steps before a report enters the human queue.
- Use AI to triage, carefully. A model can check whether the code a report cites exists or whether a reproduction runs. Keep a human decision on anything marked valid.
- Be explicit about AI. State whether AI-assisted reports are welcome and what disclosure you expect. COSMIC chose a ban; many projects will choose disclosure plus proof.
- Protect the fix window. Agree with researchers how long to wait before publishing exploit details. The HFS case shows a detailed write-up can start attacks quickly, so allow time for users to patch.
- Fund remediation, not just discovery. If you rely on open source, paying for maintainer time may do more good than paying for more findings.
The bigger picture is that AI has moved the bottleneck. For years the security industry worried it could not find bugs fast enough. Now it can find them, real and imagined, faster than people can sort and fix them. The organizations that come out ahead will be the ones that treat triage and patching as their scarce resource, and spend it on the vulnerabilities attackers are actually using. For the broader agent and model risks behind this trend, see AI agent security in 2026.
Frequently asked questions
Why did Google pause its open-source bug bounty?
Google stopped accepting product vulnerability submissions to its Open Source Software Vulnerability Reward Program from 1 October 2026 because maintainers were overwhelmed by thousands of low-quality, AI-generated reports, many describing flaws that did not exist. Reports filed earlier stay valid, supply-chain reports continue, and Google expects to share an update by Q1 2027.
What is CVE-2026-61500 in Rejetto HFS?
It is a CVSS 9.8 flaw in Rejetto HTTP File Server versions 3.0.0 to 3.2.0. HFS signed session cookies with a key made from JavaScript’s Math.random() and leaked that generator’s outputs, so an attacker could rebuild the key, forge an admin session and run code. Upgrade to HFS 3.2.1 or later.
Was the Mythos-found HFS flaw exploited?
Yes. Horizon3.ai published its write-up on 30 September 2026, and VulnCheck reported detecting exploitation the next evening, including an actor in China targeting vulnerable hosts in the US. Anyone running HFS 3.x should upgrade immediately and check for unexpected admin sessions or new files.
What is AI slop in bug bounty programs?
AI slop is the term for low-effort, AI-generated vulnerability reports filed without human checking. They often cite code that does not exist or describe impossible attacks, yet maintainers must still investigate each one. The flood has led HackerOne’s Internet Bug Bounty, curl and now Google’s OSS VRP to pause or change their programs.
Does this affect businesses that do not run bug bounties?
Yes. Almost every business depends on open-source software. When maintainers are swamped, fixes can slow down, scanners report far more CVEs, and public exploit details reach attackers faster. Prioritize patches by evidence of exploitation and internet exposure, not by severity score alone.
Should my team use AI to find vulnerabilities?
AI can help find real flaws in your own code when skilled people review and reproduce the results. Set a rule that no AI-found issue is reported to another organization or open-source project until a human has confirmed it with a working reproduction, and follow each project’s disclosure policy.
Sources
- Tom’s Hardware: Google freezes open-source bug bounty program amid flood of invalid AI submissions
- Horizon3.ai: Anthropic Mythos finds Rejetto HFS RCE
- The Register: Mythos-found flaw under attack
- Strix: CVE-2026-61500 record, CVSS and affected versions
- Linuxiac: COSMIC stops accepting LLM-generated content in pull requests
- Tom’s Hardware: Intel suspends bug bounty program that paid up to $100,000 per flaw
- Security Boulevard: AI helps drive Linux kernel CVEs to near 2,000 per release
- Gigazine: HackerOne’s Internet Bug Bounty stops accepting submissions
- Cybernews: AI is so good at finding bugs that it’s breaking bug bounty programs
