home.social

#bug-bounty — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bug-bounty, aggregated by home.social.

fetched live
  1. 🏛️ Trump wants to grant private cyber firms a license to hack back

    📝 Donald Trump is allowing government agencies to ...

    theregister.com/security/2026/

    📰 www.theregister.com - Articles

    #AI #BugBounty

  2. 🏛️ Trump wants to grant private cyber firms a license to hack back

    📝 Donald Trump is allowing government agencies to ...

    theregister.com/security/2026/

    📰 www.theregister.com - Articles

    #AI #BugBounty

  3. 10 DOM Invader sink hits. 0 vulnerabilities.

    And that's actually the lesson.

    On a real bug bounty target, the hard part isn't finding sink hits. It's quickly figuring out which ones aren't worth chasing.

    Real-world DOM XSS triage:

    medium.com/@marduk.i.am/dom-in

    #BugBounty #WebSecurity #DOMXSS #XSS #BurpSuite #DOMInvader

  4. 10 DOM Invader sink hits. 0 vulnerabilities.

    And that's actually the lesson.

    On a real bug bounty target, the hard part isn't finding sink hits. It's quickly figuring out which ones aren't worth chasing.

    Real-world DOM XSS triage:

    medium.com/@marduk.i.am/dom-in

    #BugBounty #WebSecurity #DOMXSS #XSS #BurpSuite #DOMInvader

  5. 🛡️ DEF CON hackers add new muscle to water utility protection

    📝 DEF CON hackers expanded their efforts to provide fre...

    theregister.com/security/2026/

    📰 www.theregister.com - Articles

    #BugBounty #Malware

  6. 🛡️ DEF CON hackers add new muscle to water utility protection

    📝 DEF CON hackers expanded their efforts to provide fre...

    theregister.com/security/2026/

    📰 www.theregister.com - Articles

    #BugBounty #Malware

  7. #SQLMap for #BugBounty Hunters

    We showed you different ways you can use the tool in bug bounty.

    Payloads, tampers, columns, ways to #bypass WAF and real stories were covered!

    hackers-arise.com/sql-injectio
    #Cybersecurity #ethicalhacking

  8. #SQLMap for #BugBounty Hunters

    We showed you different ways you can use the tool in bug bounty.

    Payloads, tampers, columns, ways to #bypass WAF and real stories were covered!

    hackers-arise.com/sql-injectio
    #Cybersecurity #ethicalhacking

  9. #SQLMap for #BugBounty Hunters

    We showed you different ways you can use the tool in bug bounty.

    Payloads, tampers, columns, ways to #bypass WAF and real stories were covered!

    hackers-arise.com/sql-injectio
    #Cybersecurity #ethicalhacking

  10. 🤖 CrowdRecon is coming: turning hacker reconnaissance into security intelligence

    📝 At DEF CON 34, our team introduced something exciting. Something the Intigriti team has been building for months, and...

    intigriti.com/blog/news/introd

    📰 Intigriti

    #AI #BugBounty

  11. 🤖 CrowdRecon is coming: turning hacker reconnaissance into security intelligence

    📝 At DEF CON 34, our team introduced something exciting. Something the Intigriti team has been building for months, and...

    intigriti.com/blog/news/introd

    📰 Intigriti

    #AI #BugBounty

  12. 🔒 Python Now Has a Post-Quantum Encryption Library

    📝 This is good : Post-quantum cryptography is now one pip-install away for the entire Pyth...

    schneier.com/blog/archives/202

    📰 Schneier on Security

    #BugBounty #Hacking

  13. 🔒 Python Now Has a Post-Quantum Encryption Library

    📝 This is good : Post-quantum cryptography is now one pip-install away for the entire Pyth...

    schneier.com/blog/archives/202

    📰 Schneier on Security

    #BugBounty #Hacking

  14. HackerOne était la plateforme de bug bounty de référence. Mais que se passe-t-il quand l'intermédiaire entre chercheurs et éditeurs évolue, se restructure, change de priorités ? La question posée ici n'est pas anecdotique : la santé des programmes de divulgation responsable dépend aussi de la stabilité des plateformes qui les hébergent. #infosec #bugbounty #VulnerabilityDisclosure
    blog.teknogeek.io/posts/what-h

  15. 💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
    blog.teknogeek.io/posts/what-h #techblog #humor #HackerOne #bugbounty #HackerNews #ngated

  16. 💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
    blog.teknogeek.io/posts/what-h #techblog #humor #HackerOne #bugbounty #HackerNews #ngated

  17. 💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
    blog.teknogeek.io/posts/what-h #techblog #humor #HackerOne #bugbounty #HackerNews #ngated

  18. 💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
    blog.teknogeek.io/posts/what-h #techblog #humor #HackerOne #bugbounty #HackerNews #ngated

  19. 💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
    blog.teknogeek.io/posts/what-h #techblog #humor #HackerOne #bugbounty #HackerNews #ngated

  20. How to get started for bug bounty, by hakluke (@hakluke).

    LLM in the workflow, yeah it kinda sucks... but, a hacker is the one who used available tools on their advantage.

    Though, if you are cracked, there are still chances you found something without LLM help (harder but not impossible). If you did achieve this, you can flex your muscles.

    hakluke.com/how-to-start-or-co

    #cybersecurity #bugbounty #infosec

  21. How to get started for bug bounty, by hakluke (@hakluke).

    LLM in the workflow, yeah it kinda sucks... but, a hacker is the one who used available tools on their advantage.

    Though, if you are cracked, there are still chances you found something without LLM help (harder but not impossible). If you did achieve this, you can flex your muscles.

    hakluke.com/how-to-start-or-co

    #cybersecurity #bugbounty #infosec

  22. How to get started for bug bounty, by hakluke (@hakluke).

    LLM in the workflow, yeah it kinda sucks... but, a hacker is the one who used available tools on their advantage.

    Though, if you are cracked, there are still chances you found something without LLM help (harder but not impossible). If you did achieve this, you can flex your muscles.

    hakluke.com/how-to-start-or-co

    #cybersecurity #bugbounty #infosec

  23. Welcome to the age of AI-mediated dehumanization and abuse. Ethical hackers will also be replaced by AI agents. Will it end in a machine-versus-machine apocalypse? Or will the internet become a barren, dark wasteland filled with digital ghosts? I saw this coming and quit bug bounty a long time ago; now it's impossible to ignore.

    #hackerone #bugbounty #ethicalhacking #infosec

    blog.teknogeek.io/posts/what-h

  24. Welcome to the age of AI-mediated dehumanization and abuse. Ethical hackers will also be replaced by AI agents. Will it end in a machine-versus-machine apocalypse? Or will the internet become a barren, dark wasteland filled with digital ghosts? I saw this coming and quit bug bounty a long time ago; now it's impossible to ignore.

    #hackerone #bugbounty #ethicalhacking #infosec

    blog.teknogeek.io/posts/what-h

  25. Welcome to the age of AI-mediated dehumanization and abuse. Ethical hackers will also be replaced by AI agents. Will it end in a machine-versus-machine apocalypse? Or will the internet become a barren, dark wasteland filled with digital ghosts? I saw this coming and quit bug bounty a long time ago; now it's impossible to ignore.

    #hackerone #bugbounty #ethicalhacking #infosec

    blog.teknogeek.io/posts/what-h

  26. Welcome to the age of AI-mediated dehumanization and abuse. Ethical hackers will also be replaced by AI agents. Will it end in a machine-versus-machine apocalypse? Or will the internet become a barren, dark wasteland filled with digital ghosts? I saw this coming and quit bug bounty a long time ago; now it's impossible to ignore.

    #hackerone #bugbounty #ethicalhacking #infosec

    blog.teknogeek.io/posts/what-h

  27. ☁️ The Good, the Bad and the Ugly in Cybersecurity – Week 32

    📝 The Good | Snowflake Hacker Pleads Guilty as Ransom Cartel Creator Draws 16...

    sentinelone.com/blog/the-good-

    📰 Cybersecurity Blog | SentinelOne

    #CloudSec #BugBounty

  28. ☁️ The Good, the Bad and the Ugly in Cybersecurity – Week 32

    📝 The Good | Snowflake Hacker Pleads Guilty as Ransom Cartel Creator Draws 16...

    sentinelone.com/blog/the-good-

    📰 Cybersecurity Blog | SentinelOne

    #CloudSec #BugBounty

  29. 🛡️ NatJack exploits put NAT security assumptions to the test at Black Hat

    📝 For decades, Network Address Translation (NAT) has been ...

    csoonline.com/article/4206299/

    📰 CSO Online

    #ZeroDay #BugBounty

  30. 🛡️ NatJack exploits put NAT security assumptions to the test at Black Hat

    📝 For decades, Network Address Translation (NAT) has been ...

    csoonline.com/article/4206299/

    📰 CSO Online

    #ZeroDay #BugBounty

  31. 🤖 Practical lessons from deploying AI securely at scale

    📝 When I first started working on enterprise AI security initiatives, I expected the biggest challen...

    csoonline.com/article/4205710/

    📰 CSO Online

    #AI #BugBounty

  32. 🔒 Vulnerabilities in Car Anti-Theft Device

    📝 This is disturbing: …a team of security researchers at UC San Diego, who found that a model of afterma...

    schneier.com/blog/archives/202

    📰 Schneier on Security

    #CVE #BugBounty

  33. 🔒 Vulnerabilities in Car Anti-Theft Device

    📝 This is disturbing: …a team of security researchers at UC San Diego, who found that a model of afterma...

    schneier.com/blog/archives/202

    📰 Schneier on Security

    #CVE #BugBounty

  34. Microsoft annonce 20 M$ versés en bug bounty, un record attribué en partie à l'IA. Intéressant de noter que l'IA est ici citée comme levier d'augmentation des découvertes — mais aussi comme nouvelle surface à auditer. Plus on l'intègre, plus elle entre dans le périmètre. #bugbounty #infosec #AI
    zdnet.fr/actualites/bug-bounty

  35. Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.

    #Apple #BugBounty #Cybersecurity #AI #Vulnerability

    securityonline.info/apple-bug-

  36. Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.

    #Apple #BugBounty #Cybersecurity #AI #Vulnerability

    securityonline.info/apple-bug-

  37. Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.

    #Apple #BugBounty #Cybersecurity #AI #Vulnerability

    securityonline.info/apple-bug-

  38. Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.

    #Apple #BugBounty #Cybersecurity #AI #Vulnerability

    securityonline.info/apple-bug-

  39. Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.

    #Apple #BugBounty #Cybersecurity #AI #Vulnerability

    securityonline.info/apple-bug-

  40. 💵 Intigriti named new provider for Adobe's Bug Bounty Program

    📝 Adobe empowers everyone to create through industry-leading platforms and tools that unleash...

    intigriti.com/blog/news/intigr

    📰 Intigriti

    #BugBounty #Pentesting

  41. 🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

    tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.

    What's exposed:

    • Creator emails, conference IDs, recording status, timestamps
    • Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
    • Government meetings from 23 countries
    • Corporate meetings from thousands of companies

    Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.

    Full writeup: bobdahacker.com/blog/tldv-hack

    #InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy

  42. 🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

    tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.

    What's exposed:

    • Creator emails, conference IDs, recording status, timestamps
    • Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
    • Government meetings from 23 countries
    • Corporate meetings from thousands of companies

    Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.

    Full writeup: bobdahacker.com/blog/tldv-hack

    #InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy

  43. 🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

    tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.

    What's exposed:

    • Creator emails, conference IDs, recording status, timestamps
    • Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
    • Government meetings from 23 countries
    • Corporate meetings from thousands of companies

    Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.

    Full writeup: bobdahacker.com/blog/tldv-hack

    #InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy

  44. 🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

    tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.

    What's exposed:

    • Creator emails, conference IDs, recording status, timestamps
    • Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
    • Government meetings from 23 countries
    • Corporate meetings from thousands of companies

    Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.

    Full writeup: bobdahacker.com/blog/tldv-hack

    #InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy

  45. 🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

    tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.

    What's exposed:

    • Creator emails, conference IDs, recording status, timestamps
    • Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
    • Government meetings from 23 countries
    • Corporate meetings from thousands of companies

    Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.

    Full writeup: bobdahacker.com/blog/tldv-hack

    #InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy