Google's Vulnerability Rewards Program (VRP) celebrated its 15th anniversary in 2025, awarding a record $17 million to over 700 researchers globally. The program saw significant growth, including the launch of a dedicated AI VRP and expanded reward categories for AI features within the Chrome VRP. Additionally, a new patch rewards program was introduced for the OSV-SCALIBR tool.

Google's Vulnerability Rewards Program (VRP) marked its 15th anniversary in 2025 by distributing a record $17 million in rewards to more than 700 security researchers worldwide. This annual figure represents a substantial increase in payouts and researcher participation.
The program experienced notable expansion throughout the year. A significant development was the introduction of a dedicated AI VRP, signaling Google's increased focus on the security of its artificial intelligence initiatives.
Furthermore, the Chrome VRP saw its reward categories broadened to encompass AI features integrated within the Chrome browser. This move acknowledges the growing importance of AI's role in web browsing security.
In addition to these advancements, Google launched a new patch rewards program. This initiative specifically targets contributions related to the OSV-SCALIBR tool, encouraging the development and improvement of security patching mechanisms.
The record-breaking year for the VRP underscores Google's ongoing commitment to fostering a collaborative security ecosystem. By incentivizing researchers, the company aims to proactively identify and address potential vulnerabilities across its diverse range of products and services.
The global reach of the program is highlighted by the participation of over 700 researchers from various international locations. This broad engagement allows for a diverse range of perspectives and expertise to be applied to security testing.
The sustained growth of the VRP over its 15-year history demonstrates its effectiveness as a mechanism for enhancing product security. The program's evolution, particularly its adaptation to emerging fields like AI, reflects the dynamic nature of cybersecurity threats and the need for continuous innovation in defense strategies.
The introduction of the patch rewards program for OSV-SCALIBR suggests a strategic effort to improve the efficiency and effectiveness of software updates and security fixes. This focus on post-vulnerability remediation is a critical component of a comprehensive security posture.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed