#bugbounty — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bugbounty, aggregated by home.social.
-
Yes, $150,000! Apple paid Sentry founder and CTO Drinor Selmanaj $150,000 for finding a Private Cloud Compute flaw that could allow root file writes and redirect Apple Intelligence telemetry.
Listen/Read: https://hackread.com/apple-sentry-founder-private-cloud-compute-vulnerability/
#CyberSecurity #Apple #AppleIntelligence #Vulnerability #BugBounty
-
Angriff auf Apples Private Cloud Compute: 150.000 Dollar für Sicherheitsforscher | Mac & i https://www.heise.de/news/Angriff-auf-Apples-Private-Cloud-Compute-150-000-Dollar-fuer-Sicherheitsforscher-11405384.html #Apple :apple_inc: #BugBounty
-
#SQLMap for #BugBounty Hunters
We showed you different ways you can use the tool in bug bounty.
Payloads, tampers, columns, ways to #bypass WAF and real stories were covered!
https://hackers-arise.com/sql-injections-working-with-sqlmap/
#Cybersecurity #ethicalhacking -
💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
https://blog.teknogeek.io/posts/what-happened-to-hackerone/ #techblog #humor #HackerOne #bugbounty #HackerNews #ngated -
How to get started for bug bounty, by hakluke (@hakluke).
LLM in the workflow, yeah it kinda sucks... but, a hacker is the one who used available tools on their advantage.
Though, if you are cracked, there are still chances you found something without LLM help (harder but not impossible). If you did achieve this, you can flex your muscles.
https://hakluke.com/how-to-start-or-come-back-to-bug-bounties-in-2026
-
Welcome to the age of AI-mediated dehumanization and abuse. Ethical hackers will also be replaced by AI agents. Will it end in a machine-versus-machine apocalypse? Or will the internet become a barren, dark wasteland filled with digital ghosts? I saw this coming and quit bug bounty a long time ago; now it's impossible to ignore.
-
#Apple Limits #BugBounty Submissions After Flood of #AI Slop
https://www.macrumors.com/2026/08/04/aple-bug-bounty-limits-ai/
-
Apple restricts its Bug Bounty program to combat a surge of fake AI-generated vulnerability reports, instituting caps to protect critical flaw detection.
#Apple #BugBounty #Cybersecurity #AI #Vulnerability
https://securityonline.info/apple-bug-bounty-ai/?utm_source=mastodon&utm_medium=jetpack_social
-
Inondée de faux bugs générés par l’IA, Apple limite les signalements
https://mac4ever.com/197456
#Mac4Ever #Apple #BugBounty #IA -
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
Apple aggiorna il proprio programma di #bugbounty per gestire l'ondata di segnalazioni generate da #IA. L'obiettivo è filtrare il cosiddetto AI slop per concentrarsi su vulnerabilità reali. https://kiro.it/vFIqx
-
KI-generierte Bugs: #Apple :apple_inc: zieht die Notbremse | Security https://www.heise.de/news/Apple-Limit-fuer-Bug-Meldungen-pro-Person-11395377.html #BugBounty #ArtificialIntelligence #AI #AIslop
-
Platforma HackerOne wprowadza obowiązkową weryfikację tożsamości w programach Bug Bounty
Platformy HackerOne raczej nie trzeba przedstawiać nikomu, kto interesuje się cyberbezpieczeństwem. To właśnie za jej pośrednictwem wielu hakerów zgłasza wykryte podatności, w zamian za co, oprócz uznania, otrzymują nagrody pieniężne. TLDR: Do tej pory istniała możliwość otrzymania nagrody, bez potrzeby ujawniania tożsamości. Stosując się jednak do obowiązujących regulacji, zwłaszcza tych...
-
The nature of cliques - you are either IN or OUT! GitHub is moving it's Bug Bounty program to 2 tiers.
Public submissions from Joe software dude of basic bugs will get $250, down from between $500 and $1,000 previously.
In the new invite-only VIP program basic bugs get a $1,000. VIP invitations will be based a proven history of submitting a number of valid reports. https://www.theregister.com/devops/2026/07/23/github-slashes-public-bug-bounty-payouts-as-ai-report-flood-buries-its-security-team/5277046 #GitHub #Software #Security #Bugs #SoftwareBugs #BugBounty #Rewards #Microsoft #AI #SoftwareSecurity #SoftwareBugs #Vulnerability
-
https://winbuzzer.com/2026/07/28/github-cuts-public-bug-bounties-gates-top-rewards-xcxwbn/
GitHub has cut public bug bounty payouts on July 27, capping critical rewards at $10,000 while reserving $30,000-plus payments for invited researchers.
#AI #GitHub #BugBounties #BugBounty #HackerOne #Cybersecurity #SecurityResearch
-
#GitHub slashes public #bugbounty payouts as AI report flood buries its security team
For researchers sticking with the public program, a low-severity finding that previously earned between $500 and $1,000 will now bring in $250. Medium bugs top out at $2,000 instead of $5,000, high-severity flaws have been cut from as much as $20,000 to $5,000, and the maximum reward for a critical #vulnerability falls from $30,000 to $10,000.
https://www.theregister.com/devops/2026/07/23/github-slashes-public-bug-bounty-payouts-as-ai-report-flood-buries-its-security-team/5277046 -
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
new writeup: three bugs in vinext's alpha, cloudflare's next.js reimplementation that one engineer built with an AI model in about a week for roughly $1,100 in tokens.
the good one: vinext checks middleware matchers against the path with the i18n locale prefix still on it, then strips the locale when it resolves the route. /fr/dashboard misses /dashboard/:path*, the auth middleware never runs, and the router serves /dashboard anyway.
also a middleware header allowlist that is really a merge, and reflected XSS via unescaped attribute names in the next/head serializer. reported in february, cloudflare fixed all three.
https://moltenbit.net/posts/three-bugs-in-cloudflares-vinext-alpha/
#infosec #appsec #cloudflare #nextjs #bugbounty #cybersecurity #security