Google freezes open-source bug bounty after flood of invalid automated reports
Google stopped accepting product vulnerability reports for its Open Source Software VRP on October 1, blaming a surge of automated submissions that were mostly invalid.
Cybersecurity news about “Bug Bounty”.
Google stopped accepting product vulnerability reports for its Open Source Software VRP on October 1, blaming a surge of automated submissions that were mostly invalid.
Vercel's CEO confirmed a KVM zero-day reported via the Vercel Sandbox bounty program that reportedly lets guest code gain root on the host. No CVE or patch has been published yet.