Tag: bug-bounty
-
Bug Bounty vs Penetration Testing: What the Data Shows
Key TakeawaysHackerOne’s own data shows the average pentest surfaces 12 vulnerabilities with 16 percent rated high or critical, while bug bounty programs average a higher 25 percent high or critical rate.Pentests tend to surface more systemic and architectural issues, like… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/bug-bounty-vs-penetration-testing-what-the-data-shows/
-
Mythos helps bug bounty firm find critical hidden RCE
HackerOne used Anthropic’s controversial Claude Mythos 5 model on its codebase and found a critical hidden flaw. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650013/Mythos-helps-bug-bounty-firm-find-critical-hidden-RCE
-
Bug-Bounty-Programm – Vercel will seine KI-Sandbox hacken lassen
First seen on security-insider.de Jump to article: www.security-insider.de/vercel-bug-bounty-firecracker-microvm-escape-a-efa1474537dc52d883d2e6903fe7578f/
-
The Vulnpocalypse Is Repricing the Bug Bounty Economy
The surge of AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy
-
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports – many of which were found to be describing security flaws that simply didn’t exist. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-missing-exploits
-
Microsoft Bug Bounty Payouts Reach $20 Million as Researcher Participation Surges
Microsoft paid a record $20 million to 562 bug bounty researchers as AI-assisted reporting and growing participation reshaped vulnerability discovery. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-microsoft-bug-bounty-payouts-20-million/
-
Apple Caps Open Bug-Bounty Reports After Surge in Unvalidated AI Findings
Apple is limiting some bug-bounty submissions after unvalidated AI findings increased the volume of reports in its review queue. Introduced in June, the restriction limits how many vulnerability reports each researcher can keep open at once. Researchers who reach the undisclosed cap reportedly face a 30-day wait before filing again, although they may request capacity…
-
Microsoft Paid Record $20 Million in Bug Bounties to 562 Security Researchers Worldwide
Microsoft’s Bug Bounty Program awarded over $20 million to 562 security researchers this year, marking the highest total payout and the largest number of recognized researchers in the program’s history. Contributors hailed from 64 countries, highlighting the global nature of coordinated vulnerability disclosure efforts that help protect Microsoft customers worldwide. This represents significant growth over…
-
Bug-Bounty-Rekord: Microsoft verteilt 20 Millionen US-Dollar an IT-Forscher
Microsoft hat einen neuen Rekord bei der Ausschüttung seiner Bug-Bounty-Prämien aufgestellt. Für die Forscher war das aber nicht unbedingt von Vorteil. First seen on golem.de Jump to article: www.golem.de/news/bug-bounty-rekord-microsoft-verteilt-20-millionen-us-dollar-an-it-forscher-2608-211580.html
-
HackerOne Mandates ID Verification Before Bug Bounty Report Submissions
HackerOne has rolled out a significant policy change requiring all hackers to complete identity verification before submitting reports to Bug Bounty Programs (BBPs). The update, effective immediately, aims to strengthen platform integrity and meet regulatory compliance requirements for reward payments. Under the new policy, hackers must verify their identity before becoming eligible for any bounty…
-
GitHub to implement two-tier bug bounty program amid AI-generated report surge
First seen on scworld.com Jump to article: www.scworld.com/brief/github-to-implement-two-tier-bug-bounty-program-amid-ai-generated-report-surge
-
Github reagiert auf KI-Flut: Hohe Bug-Bounty-Prämien bald nur noch für VIPs
Github überarbeitet sein Bug-Bounty-Programm. Wer sich nur auf KI verlässt und sich wenig Mühe gibt, bekommt künftig geringere Prämien. First seen on golem.de Jump to article: www.golem.de/news/github-reagiert-auf-ki-flut-hohe-bug-bounty-praemien-bald-nur-noch-fuer-profis-2607-211255.html
-
Github reagiert auf KI-Flut: Hohe Bug-Bounty-Prämien bald nur noch für Profis
Github überarbeitet sein Bug-Bounty-Programm. Wer sich nur auf KI verlässt und sich wenig Mühe gibt, bekommt künftig geringere Prämien. First seen on golem.de Jump to article: www.golem.de/news/github-reagiert-auf-ki-flut-hohe-bug-bounty-praemien-bald-nur-noch-fuer-profis-2607-211255.html
-
GitHub revamps bug bounty program with new VIP tier, payout changes
GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/github-bug-bounty-program-changes/
-
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more.Reports filed before that date, including those already in GitHub’s growing triage queue, will retain the…
-
PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate WAF Bypass and Attack Chains
Tags: ai, attack, bug-bounty, cyber, firewall, LLM, open-source, penetration-testing, tool, vulnerability, wafPENTDEM is an open-source autonomous AI pentesting daemon that integrates 34 security tools with LLM-directed analysis to automate various tasks, including reconnaissance, vulnerability discovery, evidence validation, Web Application Firewall (WAF) fingerprinting, and multi-stage attack-path modeling. This Python-based project is designed for authorized security testing and bug-bounty workflows, offering both an autonomous agent mode and a…
-
AMD faces backlash over alleged bug bounty denial and changed disclosure rules
Tags: bug-bountyFirst seen on scworld.com Jump to article: www.scworld.com/brief/amd-faces-backlash-over-denied-bug-bounty-and-changed-disclosure-rules
-
Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim’s project hijack the victim’s machine learning model upload and run code inside Google’s serving infrastructure.Palo Alto Networks Unit 42, which found and reported the bug through Google’s bug bounty program, calls the technique “Pickle in…
-
Researcher Uses AI to Hack Google, Earns $500,000 Bug Bounty
Tags: access, ai, api, attack, bug-bounty, control, cyber, flaw, framework, google, infrastructure, service, vulnerabilityResearcher Arvin Shivram has earned $500,000 in bug bounties from Google’s Vulnerability Reward Program (VRP) by deploying an AI-powered fuzzing framework against Google’s internal API infrastructure, uncovering critical access-control flaws across multiple high-impact services in under 3 months. The research began after Shivram was invited to bugSWAT Mexico in October 2025, which reignited his interest in Google’s attack surface. Recognizing that…
-
Researcher Uses AI to Hack Google, Earns $500,000 Bug Bounty
Tags: access, ai, api, attack, bug-bounty, control, cyber, flaw, framework, google, infrastructure, service, vulnerabilityResearcher Arvin Shivram has earned $500,000 in bug bounties from Google’s Vulnerability Reward Program (VRP) by deploying an AI-powered fuzzing framework against Google’s internal API infrastructure, uncovering critical access-control flaws across multiple high-impact services in under 3 months. The research began after Shivram was invited to bugSWAT Mexico in October 2025, which reignited his interest in Google’s attack surface. Recognizing that…
-
Bug Bounty Research Triggers ServiceNow Security Alert
Tags: bug-bountyBug bounty research inadvertently led organizations to believe they were being breached through their ServiceNow instances. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/bug-bounty-research-triggers-servicenow-security-alert
-
Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access
Hackers exploit CVE-2026-3300 in Everest Forms Pro to inject PHP via form fields, creating rogue admin accounts. 29,300 attempts blocked. Researcher h0xilo submitted a flaw in Everest Forms Pro for WordPress, tracked as CVE-2026-3300, to Wordfence’s bug bounty program and earned $325 for it. WPEverest patched the flaw on March 18. Wordfence published a full…
-
Bug bounty businesses bombarded with AI slop
“Never-ending” AI slop strains corporate hacking reward schemes. First seen on arstechnica.com Jump to article: arstechnica.com/ai/2026/05/bug-bounty-businesses-bombarded-with-ai-slop/
-
Google Revamps Bug Bounty Programs: Android Rewards Rise, Chrome Payouts Drop in the Age of AI
Google revamps bug bounties: Android rewards rise to $1.5M, Chrome payouts drop, shifting focus to high-impact, AI-resistant vulnerabilities. Google has announced a major overhaul of its Vulnerability Reward Programs (VRP) for Android and Chrome, marking a strategic shift in how the company approaches cybersecurity. The update comes as artificial intelligence tools are reshaping the field…
-
Jenkins Plugin Updates Fix Path Traversal and Stored XSS Bugs
The Jenkins project released a critical security advisory addressing seven vulnerabilities across multiple widely used plugins. The disclosed flaws include high-severity path traversal and stored cross-site scripting (XSS) vulnerabilities that could allow threat actors to execute arbitrary code or hijack user sessions. All vulnerabilities were responsibly disclosed through the Jenkins Bug Bounty Program, which the…
-
GPT-5.5 Bio Bug Bounty Program Aims to Improve AI Safety and Performance
OpenAI has officially launched the GPT-5.5 Bio Bug Bounty program to strengthen safeguards against emerging biological risks. As artificial intelligence models become more advanced, the potential for malicious actors to generate dangerous biological information increases. Advanced persistent threats (APTs) and lone attackers could potentially misuse large language models to accelerate harmful biological research. To address…
-
Nächste KI-Kapitulation: Nextcloud zahlt für gemeldete Lücken keine Prämien mehr
Wer Sicherheitslücken an die Nextcloud-Entwickler meldet, geht künftig leer aus. Erneut wird KI einem Bug-Bounty-Programm zum Verhängnis. First seen on golem.de Jump to article: www.golem.de/news/naechste-ki-kapitulation-nextcloud-zahlt-fuer-gemeldete-luecken-keine-praemien-mehr-2604-207914.html
-
Meta and PortSwigger drive offensive security further to find what others miss
Meta Bug Bounty and PortSwigger have formed a partnership to help security researchers sharpen their skills, collaborate more closely, and improve vulnerability discovery. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/04/20/meta-bug-bounty-portswigger-partnership/
-
Durch KI überlastet: Kein Geld mehr für Bug-Reports an Open-Source-Projekte
Internet Bug Bounty zahlt vorerst keine Prämien mehr. Das betrifft unter anderem Node.js. Der Grund: Mit KI wird viel gemeldet, aber wenig gefixt. First seen on golem.de Jump to article: www.golem.de/news/wichtiges-bug-bounty-programm-pausiert-ki-reports-ueberlasten-open-source-projekte-2604-207325.html
-
Wichtiges Bug-Bounty-Programm pausiert: KI-Reports überlasten Open-Source-Projekte
Internet Bug Bounty zahlt vorerst keine Prämien mehr. Das betrifft unter anderem Node.js. Der Grund: Mit KI wird viel gemeldet, aber wenig gefixt. First seen on golem.de Jump to article: www.golem.de/news/wichtiges-bug-bounty-programm-pausiert-ki-reports-ueberlasten-open-source-projekte-2604-207325.html

