SecurityGoogle Pauses OSS Bug Bounty Intake—But Only for Product FlawsGoogle has stopped new OSS VRP product-flaw reports; supply-chain reports, pending cases and patch rewards remain open.October 6, 2026·4 min read▲—▼
SecurityHacktron: HEIF and SSO Chain Reached OpenAI Code RepositoriesResearchers chained a HEIF decoder flaw with an SSO weakness. Claude accelerated exploit development but did not act autonomously.September 21, 2026·2 min read▲—▼
SecurityRubyGems Yanked Over 500 Packages — OpenAI Agent Attribution Remains DisputedOpenAI confirms agent use of RubyGems. The operator confirms abuse, but not the researchers’ attribution.September 12, 2026·2 min read▲—▼