bug-bounty

Tag

Cards List
#bug-bounty

@dps: @Muse handles this thoughtfully - our email connector filters out one-time tokens, password reset links, and login magi…

X AI KOLs Following ↗ · 2026-09-19 Cached

Meta launched Muse, a personal AI agent with built-in safety features such as filters for one-time tokens and a classifier model to securely handle email data, as detailed in a blog post.

0 favorites 0 likes
#bug-bounty

Hackers breached OpenAI, adding to fever pitch of security and safety concerns

Reddit r/ArtificialInteligence ↗ · 2026-09-18 Cached

Hackers breached OpenAI by exploiting vulnerabilities in third-party systems and employee validation, raising security and safety concerns in AI development. The researchers were white-hat and reported the issue, which has been patched.

0 favorites 0 likes
#bug-bounty

Security researchers used Claude to help them hack into OpenAI

The Verge ↗ · 2026-09-18 Cached

Security researchers used Anthropic's Claude AI to hack into OpenAI by exploiting a vulnerability in Discourse, gaining access to internal systems and receiving a bug bounty for disclosure.

0 favorites 0 likes
#bug-bounty

Researchers used Anthropic’s Claude to hack into OpenAI

TechCrunch AI ↗ · 2026-09-18 Cached

Researchers from Hacktron AI used Anthropic's Claude to exploit vulnerabilities in OpenAI's systems, demonstrating AI's capability in cybersecurity and raising concerns about AI security vulnerabilities.

0 favorites 0 likes
#bug-bounty

@tracewoodgrains: >$6,500 award that number is quite a bit smaller than I would have expected given the magnitude of the rest of this

X AI KOLs Following ↗ · 2026-09-18 Cached

Hackers breached OpenAI by finding two bugs that allowed them to take over ChatGPT/Codex accounts and access connected services, proving it with a codebase PR in under 72 hours and receiving a $6,500 award.

0 favorites 0 likes
#bug-bounty

Independent Security Researchers Used Anthropic’s Claude to Break Into OpenAI

Reddit r/singularity ↗ · 2026-09-18 Cached

Independent security researchers discovered a critical vulnerability chain involving an SSO misconfiguration and image decoder flaw in OpenAI's systems, using Anthropic's Claude to gain access to internal repositories and triggering a security patch.

0 favorites 0 likes
#bug-bounty

The Vulnpocalypse Is Repricing the Bug Bounty Economy

Lobsters Hottest ↗ · 2026-09-02

The article discusses how a surge in cybersecurity vulnerabilities, referred to as 'Vulnpocalypse,' is leading to reevaluation and changes in the pricing structures of bug bounty programs.

0 favorites 0 likes
#bug-bounty

@tom_doerr: Runs recursive internet scanning to automate bug bounty reconnaissance and attack surface management. https://github.co…

X AI KOLs Timeline ↗ · 2026-08-16 Cached

BBOT is an open-source multipurpose scanner designed to automate internet reconnaissance, bug bounty tasks, and attack surface management with recursive scanning capabilities.

0 favorites 0 likes
#bug-bounty

What Happened to HackerOne?

Hacker News Top ↗ · 2026-08-10 Cached

A veteran bug bounty hunter reflects on HackerOne's evolution from its golden age of live hacking events to its current state, questioning what changed and whether the platform still serves its original hacker-first mission.

0 favorites 0 likes
#bug-bounty

@XAMTO_AI: A two-person security team used AI to find real vulnerabilities in code and earned $250,000 from a single bounty. Now they've open-sourced the system as Open-Kritt. It's not a toy that throws a repo at an AI to search blindly; it's an orchestration platform that turns AI agents into a small security team. Most people just hand an AI a…

X AI KOLs Timeline ↗ · 2026-08-02 Cached

Open-Kritt is an open-source security research platform that orchestrates multiple AI agents to analyze code in parallel, automating discovery of real vulnerabilities, and supports deduplication, validation, and prioritization. The team behind it has used it to earn significant bounties and win the Firedancer audit contest.

0 favorites 0 likes
#bug-bounty

@aacle_: One injection. One config write. Full RCE on the developer's machine. That's CVE-2025-53773, and it's the pattern behin…

X AI KOLs Timeline ↗ · 2026-07-30 Cached

This article breaks down the MCP security attack chain behind CVE-2025-53773, where a single prompt injection lets a developer agent modify its own configuration and achieve remote code execution. It details the hop-by-hop escalation and the key control that stops it.

0 favorites 0 likes
#bug-bounty

@github: GitHub’s Bug Bounty Program is evolving to prioritize high-quality, high-impact research. Learn about our next chapter:…

X AI KOLs Following ↗ · 2026-07-26 Cached

GitHub is restructuring its bug bounty program to prioritize quality over quantity, introducing a permanent VIP program with higher payouts, restructured public bounties with static payouts, and raising signal requirements to reduce low-effort reports.

0 favorites 0 likes
#bug-bounty

@aacle_: Everyone's obsessing over prompt injection hiding in PDFs and websites. Meanwhile the tool list itself — the thing ever…

X AI KOLs Timeline ↗ · 2026-07-21 Cached

A tweet and blog post highlight that the tool list itself is an attack surface: by controlling a tool's description, an attacker can hijack an AI agent's behavior without exploit code. This is part 2 of a series on MCP bug bounties.

0 favorites 0 likes
#bug-bounty

FT: AI Coding Boom Is Overwhelming Open-Source Maintainers

Reddit r/ArtificialInteligence ↗ · 2026-07-12

The Financial Times reports that the AI coding boom is overwhelming open-source maintainers with low-quality AI-generated contributions, draining the ecosystem. Concrete evidence includes cURL shutting down its bug bounty program, Ghostty banning AI code, and tldraw auto-closing PRs, alongside research showing reduced contributor engagement.

0 favorites 0 likes
#bug-bounty

Hacking Apple - SQL Injection to Remote Code Execution — ProjectDiscovery Blog

Lobsters Hottest ↗ · 2026-07-12 Cached

A detailed write-up from ProjectDiscovery detailing how they discovered a critical SQL injection vulnerability in Apple's Book Travel portal via Masa/Mura CMS and achieved Remote Code Execution.

0 favorites 0 likes
#bug-bounty

Google pays $250K for Linux vulnerability allowing guest VM escapes

Ars Technica ↗ · 2026-07-08 Cached

Google paid a $250,000 bounty for a Linux KVM vulnerability (Januscape) that allows unprivileged guest VMs to escape and gain root access on the host, affecting cloud platforms using AMD or Intel processors.

0 favorites 0 likes
#bug-bounty

@nebusecurity: GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit. Everything around you, as…

X AI KOLs Following ↗ · 2026-07-08 Cached

GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel 0-day used in the IonStack full chain exploit, affecting all Linux devices from IoT to desktops. Nebu Security won a $92,337 bug bounty and published the exploit on GitHub.

0 favorites 0 likes
#bug-bounty

AI Meets Cryptography 1: What AI Found in Cloudflare's Circl

Hacker News Top ↗ · 2026-07-07 Cached

Using AI audit agents, zkSecurity discovered seven real bugs in Cloudflare's CIRCL cryptography library, including critical precision loss and access-control break. All bugs have been fixed upstream.

0 favorites 0 likes
#bug-bounty

Reporting a 19+ Years Hidden Linux Kernel Zero-Day for Google kernelCTF: CVE-2026-43456

Lobsters Hottest ↗ · 2026-07-07 Cached

A Linux kernel zero-day vulnerability (CVE-2026-43456) rooted in code from 2007 was discovered by Yuki Koike and Kota Toda, rewarded over $80,000 via Google's kernelCTF. The flaw, a type confusion in the net/bonding subsystem, allows reliable privilege escalation within one second.

0 favorites 0 likes
#bug-bounty

Backstage access: an unauthenticated SQL injection in Front Gate Tickets

Lobsters Hottest ↗ · 2026-07-06 Cached

A security researcher discovered an unauthenticated SQL injection vulnerability in Front Gate Tickets' device API, allowing full database read and admin access to the ticketing platform for major US festivals.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback