#bug-bounty — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bug-bounty, aggregated by home.social.
-
🏛️ Trump wants to grant private cyber firms a license to hack back
📝 Donald Trump is allowing government agencies to ...
📰 www.theregister.com - Articles
-
🏛️ Trump wants to grant private cyber firms a license to hack back
📝 Donald Trump is allowing government agencies to ...
📰 www.theregister.com - Articles
-
10 DOM Invader sink hits. 0 vulnerabilities.
And that's actually the lesson.
On a real bug bounty target, the hard part isn't finding sink hits. It's quickly figuring out which ones aren't worth chasing.
Real-world DOM XSS triage:
-
10 DOM Invader sink hits. 0 vulnerabilities.
And that's actually the lesson.
On a real bug bounty target, the hard part isn't finding sink hits. It's quickly figuring out which ones aren't worth chasing.
Real-world DOM XSS triage:
-
Angriff auf Apples Private Cloud Compute: 150.000 Dollar für Sicherheitsforscher | Mac & i https://www.heise.de/news/Angriff-auf-Apples-Private-Cloud-Compute-150-000-Dollar-fuer-Sicherheitsforscher-11405384.html #Apple :apple_inc: #BugBounty
-
Angriff auf Apples Private Cloud Compute: 150.000 Dollar für Sicherheitsforscher | Mac & i https://www.heise.de/news/Angriff-auf-Apples-Private-Cloud-Compute-150-000-Dollar-fuer-Sicherheitsforscher-11405384.html #Apple :apple_inc: #BugBounty
-
Angriff auf Apples Private Cloud Compute: 150.000 Dollar für Sicherheitsforscher | Mac & i https://www.heise.de/news/Angriff-auf-Apples-Private-Cloud-Compute-150-000-Dollar-fuer-Sicherheitsforscher-11405384.html #Apple :apple_inc: #BugBounty
-
Angriff auf Apples Private Cloud Compute: 150.000 Dollar für Sicherheitsforscher | Mac & i https://www.heise.de/news/Angriff-auf-Apples-Private-Cloud-Compute-150-000-Dollar-fuer-Sicherheitsforscher-11405384.html #Apple :apple_inc: #BugBounty
-
Angriff auf Apples Private Cloud Compute: 150.000 Dollar für Sicherheitsforscher | Mac & i https://www.heise.de/news/Angriff-auf-Apples-Private-Cloud-Compute-150-000-Dollar-fuer-Sicherheitsforscher-11405384.html #Apple :apple_inc: #BugBounty
-
🛡️ DEF CON hackers add new muscle to water utility protection
📝 DEF CON hackers expanded their efforts to provide fre...
📰 www.theregister.com - Articles
-
🛡️ DEF CON hackers add new muscle to water utility protection
📝 DEF CON hackers expanded their efforts to provide fre...
📰 www.theregister.com - Articles
-
#SQLMap for #BugBounty Hunters
We showed you different ways you can use the tool in bug bounty.
Payloads, tampers, columns, ways to #bypass WAF and real stories were covered!
https://hackers-arise.com/sql-injections-working-with-sqlmap/
#Cybersecurity #ethicalhacking -
#SQLMap for #BugBounty Hunters
We showed you different ways you can use the tool in bug bounty.
Payloads, tampers, columns, ways to #bypass WAF and real stories were covered!
https://hackers-arise.com/sql-injections-working-with-sqlmap/
#Cybersecurity #ethicalhacking -
#SQLMap for #BugBounty Hunters
We showed you different ways you can use the tool in bug bounty.
Payloads, tampers, columns, ways to #bypass WAF and real stories were covered!
https://hackers-arise.com/sql-injections-working-with-sqlmap/
#Cybersecurity #ethicalhacking -
🤖 CrowdRecon is coming: turning hacker reconnaissance into security intelligence
📝 At DEF CON 34, our team introduced something exciting. Something the Intigriti team has been building for months, and...
https://www.intigriti.com/blog/news/introducing-crowdrecon
📰 Intigriti
-
🤖 CrowdRecon is coming: turning hacker reconnaissance into security intelligence
📝 At DEF CON 34, our team introduced something exciting. Something the Intigriti team has been building for months, and...
https://www.intigriti.com/blog/news/introducing-crowdrecon
📰 Intigriti
-
🔒 Python Now Has a Post-Quantum Encryption Library
📝 This is good : Post-quantum cryptography is now one pip-install away for the entire Pyth...
https://www.schneier.com/blog/archives/2026/08/python-now-has-a-post-quantum-encryption-library.html
📰 Schneier on Security
-
🔒 Python Now Has a Post-Quantum Encryption Library
📝 This is good : Post-quantum cryptography is now one pip-install away for the entire Pyth...
https://www.schneier.com/blog/archives/2026/08/python-now-has-a-post-quantum-encryption-library.html
📰 Schneier on Security
-
HackerOne était la plateforme de bug bounty de référence. Mais que se passe-t-il quand l'intermédiaire entre chercheurs et éditeurs évolue, se restructure, change de priorités ? La question posée ici n'est pas anecdotique : la santé des programmes de divulgation responsable dépend aussi de la stabilité des plateformes qui les hébergent. #infosec #bugbounty #VulnerabilityDisclosure
https://blog.teknogeek.io/posts/what-happened-to-hackerone/ -
💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
https://blog.teknogeek.io/posts/what-happened-to-hackerone/ #techblog #humor #HackerOne #bugbounty #HackerNews #ngated -
💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
https://blog.teknogeek.io/posts/what-happened-to-hackerone/ #techblog #humor #HackerOne #bugbounty #HackerNews #ngated -
💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
https://blog.teknogeek.io/posts/what-happened-to-hackerone/ #techblog #humor #HackerOne #bugbounty #HackerNews #ngated -
💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
https://blog.teknogeek.io/posts/what-happened-to-hackerone/ #techblog #humor #HackerOne #bugbounty #HackerNews #ngated -
💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
https://blog.teknogeek.io/posts/what-happened-to-hackerone/ #techblog #humor #HackerOne #bugbounty #HackerNews #ngated -
How to get started for bug bounty, by hakluke (@hakluke).
LLM in the workflow, yeah it kinda sucks... but, a hacker is the one who used available tools on their advantage.
Though, if you are cracked, there are still chances you found something without LLM help (harder but not impossible). If you did achieve this, you can flex your muscles.
https://hakluke.com/how-to-start-or-come-back-to-bug-bounties-in-2026
-
How to get started for bug bounty, by hakluke (@hakluke).
LLM in the workflow, yeah it kinda sucks... but, a hacker is the one who used available tools on their advantage.
Though, if you are cracked, there are still chances you found something without LLM help (harder but not impossible). If you did achieve this, you can flex your muscles.
https://hakluke.com/how-to-start-or-come-back-to-bug-bounties-in-2026
-
How to get started for bug bounty, by hakluke (@hakluke).
LLM in the workflow, yeah it kinda sucks... but, a hacker is the one who used available tools on their advantage.
Though, if you are cracked, there are still chances you found something without LLM help (harder but not impossible). If you did achieve this, you can flex your muscles.
https://hakluke.com/how-to-start-or-come-back-to-bug-bounties-in-2026
-
Welcome to the age of AI-mediated dehumanization and abuse. Ethical hackers will also be replaced by AI agents. Will it end in a machine-versus-machine apocalypse? Or will the internet become a barren, dark wasteland filled with digital ghosts? I saw this coming and quit bug bounty a long time ago; now it's impossible to ignore.
-
Welcome to the age of AI-mediated dehumanization and abuse. Ethical hackers will also be replaced by AI agents. Will it end in a machine-versus-machine apocalypse? Or will the internet become a barren, dark wasteland filled with digital ghosts? I saw this coming and quit bug bounty a long time ago; now it's impossible to ignore.
-
Welcome to the age of AI-mediated dehumanization and abuse. Ethical hackers will also be replaced by AI agents. Will it end in a machine-versus-machine apocalypse? Or will the internet become a barren, dark wasteland filled with digital ghosts? I saw this coming and quit bug bounty a long time ago; now it's impossible to ignore.
-
Welcome to the age of AI-mediated dehumanization and abuse. Ethical hackers will also be replaced by AI agents. Will it end in a machine-versus-machine apocalypse? Or will the internet become a barren, dark wasteland filled with digital ghosts? I saw this coming and quit bug bounty a long time ago; now it's impossible to ignore.
-
☁️ The Good, the Bad and the Ugly in Cybersecurity – Week 32
📝 The Good | Snowflake Hacker Pleads Guilty as Ransom Cartel Creator Draws 16...
https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-32-8/
📰 Cybersecurity Blog | SentinelOne
-
☁️ The Good, the Bad and the Ugly in Cybersecurity – Week 32
📝 The Good | Snowflake Hacker Pleads Guilty as Ransom Cartel Creator Draws 16...
https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-32-8/
📰 Cybersecurity Blog | SentinelOne
-
🛡️ NatJack exploits put NAT security assumptions to the test at Black Hat
📝 For decades, Network Address Translation (NAT) has been ...
📰 CSO Online
-
🛡️ NatJack exploits put NAT security assumptions to the test at Black Hat
📝 For decades, Network Address Translation (NAT) has been ...
📰 CSO Online
-
#Apple Limits #BugBounty Submissions After Flood of #AI Slop
https://www.macrumors.com/2026/08/04/aple-bug-bounty-limits-ai/
-
#Apple Limits #BugBounty Submissions After Flood of #AI Slop
https://www.macrumors.com/2026/08/04/aple-bug-bounty-limits-ai/
-
#Apple Limits #BugBounty Submissions After Flood of #AI Slop
https://www.macrumors.com/2026/08/04/aple-bug-bounty-limits-ai/
-
#Apple Limits #BugBounty Submissions After Flood of #AI Slop
https://www.macrumors.com/2026/08/04/aple-bug-bounty-limits-ai/
-
#Apple Limits #BugBounty Submissions After Flood of #AI Slop
https://www.macrumors.com/2026/08/04/aple-bug-bounty-limits-ai/
-
🤖 Practical lessons from deploying AI securely at scale
📝 When I first started working on enterprise AI security initiatives, I expected the biggest challen...
https://www.csoonline.com/article/4205710/practical-lessons-from-deploying-ai-securely-at-scale.html
📰 CSO Online
-
🔒 Vulnerabilities in Car Anti-Theft Device
📝 This is disturbing: …a team of security researchers at UC San Diego, who found that a model of afterma...
https://www.schneier.com/blog/archives/2026/08/vulnerabilities-in-car-anti-theft-device.html
📰 Schneier on Security
-
🔒 Vulnerabilities in Car Anti-Theft Device
📝 This is disturbing: …a team of security researchers at UC San Diego, who found that a model of afterma...
https://www.schneier.com/blog/archives/2026/08/vulnerabilities-in-car-anti-theft-device.html
📰 Schneier on Security
-
Microsoft annonce 20 M$ versés en bug bounty, un record attribué en partie à l'IA. Intéressant de noter que l'IA est ici citée comme levier d'augmentation des découvertes — mais aussi comme nouvelle surface à auditer. Plus on l'intègre, plus elle entre dans le périmètre. #bugbounty #infosec #AI
https://www.zdnet.fr/actualites/bug-bounty-microsoft-verse-20-millions-de-dollars-un-record-dope-par-lia-499302.htm#xtor=RSS-1 -
Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.
#Apple #BugBounty #Cybersecurity #AI #Vulnerability
https://securityonline.info/apple-bug-bounty-ai/?utm_source=mastodon&utm_medium=jetpack_social
-
Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.
#Apple #BugBounty #Cybersecurity #AI #Vulnerability
https://securityonline.info/apple-bug-bounty-ai/?utm_source=mastodon&utm_medium=jetpack_social
-
Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.
#Apple #BugBounty #Cybersecurity #AI #Vulnerability
https://securityonline.info/apple-bug-bounty-ai/?utm_source=mastodon&utm_medium=jetpack_social
-
Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.
#Apple #BugBounty #Cybersecurity #AI #Vulnerability
https://securityonline.info/apple-bug-bounty-ai/?utm_source=mastodon&utm_medium=jetpack_social
-
Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.
#Apple #BugBounty #Cybersecurity #AI #Vulnerability
https://securityonline.info/apple-bug-bounty-ai/?utm_source=mastodon&utm_medium=jetpack_social
-
Inondée de faux bugs générés par l’IA, Apple limite les signalements
https://mac4ever.com/197456
#Mac4Ever #Apple #BugBounty #IA -
Inondée de faux bugs générés par l’IA, Apple limite les signalements
https://mac4ever.com/197456
#Mac4Ever #Apple #BugBounty #IA -
Inondée de faux bugs générés par l’IA, Apple limite les signalements
https://mac4ever.com/197456
#Mac4Ever #Apple #BugBounty #IA -
Inondée de faux bugs générés par l’IA, Apple limite les signalements
https://mac4ever.com/197456
#Mac4Ever #Apple #BugBounty #IA -
Inondée de faux bugs générés par l’IA, Apple limite les signalements
https://mac4ever.com/197456
#Mac4Ever #Apple #BugBounty #IA -
💵 Intigriti named new provider for Adobe's Bug Bounty Program
📝 Adobe empowers everyone to create through industry-leading platforms and tools that unleash...
https://www.intigriti.com/blog/news/intigriti-named-new-provider-for-adobes-bug-bounty-program
📰 Intigriti
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy