#hackerone — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #hackerone, aggregated by home.social.
-
HackerOne Bug Bounty Disclosure: debug-deep-link-abuse-allows-repeated-forced-logout-and-application-disruption-karim-mohamed - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-debug-deep-link-abuse-allows-repeated-forced-logout-and-application-disruption-karim-mohamed/
-
HackerOne Bug Bounty Disclosure: debug-deep-link-abuse-allows-repeated-forced-logout-and-application-disruption-karim-mohamed - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-debug-deep-link-abuse-allows-repeated-forced-logout-and-application-disruption-karim-mohamed/
-
HackerOne Bug Bounty Disclosure: -myndr-cors-misconfiguration-shubham - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-myndr-cors-misconfiguration-shubham-2/
-
HackerOne Bug Bounty Disclosure: -myndr-cors-misconfiguration-shubham - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-myndr-cors-misconfiguration-shubham-2/
-
HackerOne Bug Bounty Disclosure: jaas-sip-gateway-authorization-bypass-offseq - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-jaas-sip-gateway-authorization-bypass-offseq/
-
HackerOne Bug Bounty Disclosure: -myndr-cors-misconfiguration-shubham - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-myndr-cors-misconfiguration-shubham/
-
HackerOne Bug Bounty Disclosure: jaas-sip-gateway-authorization-bypass-offseq - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-jaas-sip-gateway-authorization-bypass-offseq/
-
HackerOne Bug Bounty Disclosure: -myndr-cors-misconfiguration-shubham - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-myndr-cors-misconfiguration-shubham/
-
What Happened to HackerOne? How the Bug Bounty Pioneer Became an AI Security Company
What happened to HackerOne? A deep look at its bug bounty roots, AI strategy, Hai, researcher data, continuous testing and futurehttps://thecybersecguru.com/analysis/what-happened-to-hackerone/
-
What Happened to HackerOne? How the Bug Bounty Pioneer Became an AI Security Company
What happened to HackerOne? A deep look at its bug bounty roots, AI strategy, Hai, researcher data, continuous testing and futurehttps://thecybersecguru.com/analysis/what-happened-to-hackerone/
-
💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
https://blog.teknogeek.io/posts/what-happened-to-hackerone/ #techblog #humor #HackerOne #bugbounty #HackerNews #ngated -
💻 Oh, look! Another "witty" tech blog post dissecting the fall of a company—HackerOne this time—by a self-proclaimed bug bounty oracle. 🙄 But don't worry, there's a table of contents to guide you through this groundbreaking #analysis, because who doesn't want #chaos with their curiosity? 😂
https://blog.teknogeek.io/posts/what-happened-to-hackerone/ #techblog #humor #HackerOne #bugbounty #HackerNews #ngated -
What Happened to HackerOne?
https://blog.teknogeek.io/posts/what-happened-to-hackerone/
Comments: https://news.ycombinator.com/item?id=49238561
#HackerNews #HackerOne #HackerNews #cybersecurity #technews #blogpost
-
What Happened to HackerOne?
https://blog.teknogeek.io/posts/what-happened-to-hackerone/
Comments: https://news.ycombinator.com/item?id=49238561
#HackerNews #HackerOne #HackerNews #cybersecurity #technews #blogpost
-
Welcome to the age of AI-mediated dehumanization and abuse. Ethical hackers will also be replaced by AI agents. Will it end in a machine-versus-machine apocalypse? Or will the internet become a barren, dark wasteland filled with digital ghosts? I saw this coming and quit bug bounty a long time ago; now it's impossible to ignore.
-
Blogpost made by teknogeek (@teknogeek ) regarding the situation... downfall of 'hacker'one.... sorry I mean, salesone.
And they also start to introduce 'digital ID verification', which excuse to combat 'ai slop reports'. It throws everything out of their 'hacker' brand. lol
-
Blogpost made by teknogeek (@teknogeek ) regarding the situation... downfall of 'hacker'one.... sorry I mean, salesone.
And they also start to introduce 'digital ID verification', which excuse to combat 'ai slop reports'. It throws everything out of their 'hacker' brand. lol
-
HackerOne Bug Bounty Disclosure: github-retired-usernametakeover-from-aws-shad-w - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-github-retired-usernametakeover-from-aws-shad-w/
-
HackerOne Bug Bounty Disclosure: heap-use-after-free-write-in-mev-forget-socket-via-reentrant-curl-easy-pause-incomplete-fix-for-cve-juthawong-naisanguansee - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-heap-use-after-free-write-in-mev-forget-socket-via-reentrant-curl-easy-pause-incomplete-fix-for-cve-juthawong-naisanguansee/
-
HackerOne Bug Bounty Disclosure: github-retired-usernametakeover-from-aws-shad-w - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-github-retired-usernametakeover-from-aws-shad-w/
-
HackerOne Bug Bounty Disclosure: heap-use-after-free-write-in-mev-forget-socket-via-reentrant-curl-easy-pause-incomplete-fix-for-cve-juthawong-naisanguansee - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-heap-use-after-free-write-in-mev-forget-socket-via-reentrant-curl-easy-pause-incomplete-fix-for-cve-juthawong-naisanguansee/
-
HackerOne Bug Bounty Disclosure: smtp-crlf-injection-in-custom-smtp-recipient-operand-allows-additional-smtp-commands-after-authentication-dark-river - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-smtp-crlf-injection-in-custom-smtp-recipient-operand-allows-additional-smtp-commands-after-authentication-dark-river/
-
HackerOne Bug Bounty Disclosure: unauthenticated-path-traversal-lfi-via-custom-sounds-when-customsounds-uses-filesystem-storage-s - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-unauthenticated-path-traversal-lfi-via-custom-sounds-when-customsounds-uses-filesystem-storage-s/
-
HackerOne Bug Bounty Disclosure: smtp-crlf-injection-in-custom-smtp-recipient-operand-allows-additional-smtp-commands-after-authentication-dark-river - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-smtp-crlf-injection-in-custom-smtp-recipient-operand-allows-additional-smtp-commands-after-authentication-dark-river/
-
HackerOne Bug Bounty Disclosure: unauthenticated-path-traversal-lfi-via-custom-sounds-when-customsounds-uses-filesystem-storage-s - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-unauthenticated-path-traversal-lfi-via-custom-sounds-when-customsounds-uses-filesystem-storage-s/
-
Platforma HackerOne wprowadza obowiązkową weryfikację tożsamości w programach Bug Bounty
Platformy HackerOne raczej nie trzeba przedstawiać nikomu, kto interesuje się cyberbezpieczeństwem. To właśnie za jej pośrednictwem wielu hakerów zgłasza wykryte podatności, w zamian za co, oprócz uznania, otrzymują nagrody pieniężne. TLDR: Do tej pory istniała możliwość otrzymania nagrody, bez potrzeby ujawniania tożsamości. Stosując się jednak do obowiązujących regulacji, zwłaszcza tych...
-
Platforma HackerOne wprowadza obowiązkową weryfikację tożsamości w programach Bug Bounty
Platformy HackerOne raczej nie trzeba przedstawiać nikomu, kto interesuje się cyberbezpieczeństwem. To właśnie za jej pośrednictwem wielu hakerów zgłasza wykryte podatności, w zamian za co, oprócz uznania, otrzymują nagrody pieniężne. TLDR: Do tej pory istniała możliwość otrzymania nagrody, bez potrzeby ujawniania tożsamości. Stosując się jednak do obowiązujących regulacji, zwłaszcza tych...
-
HackerOne Bug Bounty Disclosure: unauthenticated-team-income-payments-export-ignores-donor-privacy-settings-hide-giving-hide-from-lists-and-uses-frozen-visibility-exposing-donat-ali-khaled - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-unauthenticated-team-income-payments-export-ignores-donor-privacy-settings-hide-giving-hide-from-lists-and-uses-frozen-visibility-exposing-donat-ali-khaled/
-
HackerOne Bug Bounty Disclosure: http-request-smuggling-via-connection-close-tab-in-node-js-llhxxp-parser-nadav-magier - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-http-request-smuggling-via-connection-close-tab-in-node-js-llhxxp-parser-nadav-magier/
-
HackerOne Bug Bounty Disclosure: stored-xss-in-nameserver-field-on-account-settings-page-axolot - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-stored-xss-in-nameserver-field-on-account-settings-page-axolot/
-
HackerOne Bug Bounty Disclosure: unauthenticated-team-income-payments-export-ignores-donor-privacy-settings-hide-giving-hide-from-lists-and-uses-frozen-visibility-exposing-donat-ali-khaled - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-unauthenticated-team-income-payments-export-ignores-donor-privacy-settings-hide-giving-hide-from-lists-and-uses-frozen-visibility-exposing-donat-ali-khaled/
-
HackerOne Bug Bounty Disclosure: http-request-smuggling-via-connection-close-tab-in-node-js-llhxxp-parser-nadav-magier - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-http-request-smuggling-via-connection-close-tab-in-node-js-llhxxp-parser-nadav-magier/
-
HackerOne Bug Bounty Disclosure: stored-xss-in-nameserver-field-on-account-settings-page-axolot - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-stored-xss-in-nameserver-field-on-account-settings-page-axolot/
-
Got this info via @InternationalCyberDigest. For a company having "hacker" in their name, this is an insult towards hacking community.
If you value the 'hacker' value, DO NOT SUPPORT any form of ID Verification. Fight this shit to oblivion. If you are in only for the money, do not mind YOUR ID handled by 3rd party (meaning you should not call yourself a hacker), then sure, embrace this.
https://docs.hackerone.com/en/articles/8399430-id-verification
-
HackerOne Bug Bounty Disclosure: https-agent-pfx-object-array-key-collision-allows-mtls-client-identity-reuse-across-different-per-request-certificates-yottt - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-https-agent-pfx-object-array-key-collision-allows-mtls-client-identity-reuse-across-different-per-request-certificates-yottt/
-
HackerOne Bug Bounty Disclosure: permission-model-bypass-process-report-writes-and-overwrites-files-outside-allow-fs-write-paths-sinan-polat - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-permission-model-bypass-process-report-writes-and-overwrites-files-outside-allow-fs-write-paths-sinan-polat/
-
HackerOne Bug Bounty Disclosure: permission-model-bypass-trace-events-createtracing-enable-writes-trace-logs-outside-allow-fs-write-sir-bugs - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-permission-model-bypass-trace-events-createtracing-enable-writes-trace-logs-outside-allow-fs-write-sir-bugs/
-
HackerOne Bug Bounty Disclosure: https-agent-tls-session-reuse-skips-hostname-verification-across-identity-policies-incomplete-fix-of-cve-vnyuh - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-https-agent-tls-session-reuse-skips-hostname-verification-across-identity-policies-incomplete-fix-of-cve-vnyuh/
-
HackerOne Bug Bounty Disclosure: exportreportpdf-mutation-shows-internal-activity-kimingi - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-exportreportpdf-mutation-shows-internal-activity-kimingi/
-
HackerOne Bug Bounty Disclosure: permission-model-allow-fs-read-allow-fs-write-radix-tree-prefix-boundary-over-grant-jiyong-yang - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-permission-model-allow-fs-read-allow-fs-write-radix-tree-prefix-boundary-over-grant-jiyong-yang/
-
HackerOne Bug Bounty Disclosure: stored-xss-via-svg-upload-check-content-blocklist-bypass-byte-scan-limit-self-propagating-worm-ammar-y-sami - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-stored-xss-via-svg-upload-check-content-blocklist-bypass-byte-scan-limit-self-propagating-worm-ammar-y-sami/
-
HackerOne Bug Bounty Disclosure: github-scoped-user-to-server-tokens-can-escape-their-installation-ahacker - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-github-scoped-user-to-server-tokens-can-escape-their-installation-ahacker/
-
HackerOne Bug Bounty Disclosure: active-storage-vips-transformer-missing-validate-transformation-cve-incomplete-fix-friedchicken - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-active-storage-vips-transformer-missing-validate-transformation-cve-incomplete-fix-friedchicken/
-
HackerOne Bug Bounty Disclosure: https-agent-pfx-object-array-key-collision-allows-mtls-client-identity-reuse-across-different-per-request-certificates-yottt - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-https-agent-pfx-object-array-key-collision-allows-mtls-client-identity-reuse-across-different-per-request-certificates-yottt/
-
HackerOne Bug Bounty Disclosure: permission-model-bypass-trace-events-createtracing-enable-writes-trace-logs-outside-allow-fs-write-sir-bugs - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-permission-model-bypass-trace-events-createtracing-enable-writes-trace-logs-outside-allow-fs-write-sir-bugs/
-
HackerOne Bug Bounty Disclosure: exportreportpdf-mutation-shows-internal-activity-kimingi - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-exportreportpdf-mutation-shows-internal-activity-kimingi/
-
HackerOne Bug Bounty Disclosure: permission-model-bypass-process-report-writes-and-overwrites-files-outside-allow-fs-write-paths-sinan-polat - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-permission-model-bypass-process-report-writes-and-overwrites-files-outside-allow-fs-write-paths-sinan-polat/
-
HackerOne Bug Bounty Disclosure: permission-model-allow-fs-read-allow-fs-write-radix-tree-prefix-boundary-over-grant-jiyong-yang - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-permission-model-allow-fs-read-allow-fs-write-radix-tree-prefix-boundary-over-grant-jiyong-yang/
-
HackerOne Bug Bounty Disclosure: https-agent-tls-session-reuse-skips-hostname-verification-across-identity-policies-incomplete-fix-of-cve-vnyuh - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-https-agent-tls-session-reuse-skips-hostname-verification-across-identity-policies-incomplete-fix-of-cve-vnyuh/
-
HackerOne Bug Bounty Disclosure: github-scoped-user-to-server-tokens-can-escape-their-installation-ahacker - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-github-scoped-user-to-server-tokens-can-escape-their-installation-ahacker/
-
HackerOne Bug Bounty Disclosure: active-storage-vips-transformer-missing-validate-transformation-cve-incomplete-fix-friedchicken - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-active-storage-vips-transformer-missing-validate-transformation-cve-incomplete-fix-friedchicken/
-
HackerOne Bug Bounty Disclosure: stored-xss-via-svg-upload-check-content-blocklist-bypass-byte-scan-limit-self-propagating-worm-ammar-y-sami - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-stored-xss-via-svg-upload-check-content-blocklist-bypass-byte-scan-limit-self-propagating-worm-ammar-y-sami/
-
https://winbuzzer.com/2026/07/28/github-cuts-public-bug-bounties-gates-top-rewards-xcxwbn/
GitHub has cut public bug bounty payouts on July 27, capping critical rewards at $10,000 while reserving $30,000-plus payments for invited researchers.
#AI #GitHub #BugBounties #BugBounty #HackerOne #Cybersecurity #SecurityResearch
-
HackerOne Bug Bounty Disclosure: able-to-bypass-authorization-logic-and-gain-more-access-then-intended-vaib-vicky - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-able-to-bypass-authorization-logic-and-gain-more-access-then-intended-vaib-vicky/
-
HackerOne Bug Bounty Disclosure: bedrock-agentcore-starter-toolkit-creates-gateway-iam-roles-without-confused-deputy-protections-mistercloudsec - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-bedrock-agentcore-starter-toolkit-creates-gateway-iam-roles-without-confused-deputy-protections-mistercloudsec/
-
Cursor 會執行 repository 內 git.exe 的問題還沒修正
#ace #advisory #arbitrary #ciso #code #cursor #editor #execution #git #hackerone #ide #mindgard #process #security #windows
-
HackerOne Bug Bounty Disclosure: any-installed-app-can-force-immediate-logout-and-persistent-dos-of-authenticated-basecamp-sessions-via-unprotected-exported-startactivity-zerodaysec-xyz - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-any-installed-app-can-force-immediate-logout-and-persistent-dos-of-authenticated-basecamp-sessions-via-unprotected-exported-startactivity-zerodaysec-xyz/