bug-bounty

Tag

Cards List
#bug-bounty

@aacle_: Everyone's obsessing over prompt injection hiding in PDFs and websites. Meanwhile the tool list itself — the thing ever…

X AI KOLs Timeline · 2d ago Cached

A tweet and blog post highlight that the tool list itself is an attack surface: by controlling a tool's description, an attacker can hijack an AI agent's behavior without exploit code. This is part 2 of a series on MCP bug bounties.

0 favorites 0 likes
#bug-bounty

FT: AI Coding Boom Is Overwhelming Open-Source Maintainers

Reddit r/ArtificialInteligence · 2026-07-12

The Financial Times reports that the AI coding boom is overwhelming open-source maintainers with low-quality AI-generated contributions, draining the ecosystem. Concrete evidence includes cURL shutting down its bug bounty program, Ghostty banning AI code, and tldraw auto-closing PRs, alongside research showing reduced contributor engagement.

0 favorites 0 likes
#bug-bounty

Hacking Apple - SQL Injection to Remote Code Execution — ProjectDiscovery Blog

Lobsters Hottest · 2026-07-12 Cached

A detailed write-up from ProjectDiscovery detailing how they discovered a critical SQL injection vulnerability in Apple's Book Travel portal via Masa/Mura CMS and achieved Remote Code Execution.

0 favorites 0 likes
#bug-bounty

Google pays $250K for Linux vulnerability allowing guest VM escapes

Ars Technica · 2026-07-08 Cached

Google paid a $250,000 bounty for a Linux KVM vulnerability (Januscape) that allows unprivileged guest VMs to escape and gain root access on the host, affecting cloud platforms using AMD or Intel processors.

0 favorites 0 likes
#bug-bounty

@nebusecurity: GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit. Everything around you, as…

X AI KOLs Following · 2026-07-08 Cached

GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel 0-day used in the IonStack full chain exploit, affecting all Linux devices from IoT to desktops. Nebu Security won a $92,337 bug bounty and published the exploit on GitHub.

0 favorites 0 likes
#bug-bounty

AI Meets Cryptography 1: What AI Found in Cloudflare's Circl

Hacker News Top · 2026-07-07 Cached

Using AI audit agents, zkSecurity discovered seven real bugs in Cloudflare's CIRCL cryptography library, including critical precision loss and access-control break. All bugs have been fixed upstream.

0 favorites 0 likes
#bug-bounty

Reporting a 19+ Years Hidden Linux Kernel Zero-Day for Google kernelCTF: CVE-2026-43456

Lobsters Hottest · 2026-07-07 Cached

A Linux kernel zero-day vulnerability (CVE-2026-43456) rooted in code from 2007 was discovered by Yuki Koike and Kota Toda, rewarded over $80,000 via Google's kernelCTF. The flaw, a type confusion in the net/bonding subsystem, allows reliable privilege escalation within one second.

0 favorites 0 likes
#bug-bounty

Backstage access: an unauthenticated SQL injection in Front Gate Tickets

Lobsters Hottest · 2026-07-06 Cached

A security researcher discovered an unauthenticated SQL injection vulnerability in Front Gate Tickets' device API, allowing full database read and admin access to the ticketing platform for major US festivals.

0 favorites 0 likes
#bug-bounty

@0x0SojalSec: Reverse Engineer Any Android APK with AI Apktool + any LLMs or local Ollama) for real-time decompiling, Smali analysis,…

X AI KOLs Timeline · 2026-07-01 Cached

A tool that integrates AI (any LLM or local Ollama) with Apktool to enable real-time decompiling, Smali analysis, manifest review, vulnerability hunting, and live patching of Android APKs via natural language.

0 favorites 0 likes
#bug-bounty

Humiliating IIS servers for fun and jail time

Hacker News Top · 2026-06-16 Cached

A detailed technical guide on discovering and exploiting misconfigured IIS servers for bug bounty hunting, covering techniques like Shodan queries, tilde enumeration, web.config exploitation, and WAF bypass.

0 favorites 0 likes
#bug-bounty

Anthropic disputes the Claude Fable 5 jailbreak after a researcher posted its 120,000-character system prompt

Reddit r/ArtificialInteligence · 2026-06-15

Anthropic disputes claims that its Claude Fable 5 model was jailbroken within a day of launch, arguing the researcher's method was coaxing rather than a true breach of core safeguards, and points to extensive bug-bounty testing.

0 favorites 0 likes
#bug-bounty

@XAMTO_AI: Stop using Claude Code as a chatbot. Those who really know how to play have already filled it with hacker brains. 51 practical skills, 574+ report templates, 24 types of vulnerability tactics — one-click install, turning a noob into a seasoned bounty hunter. You're still watching, while others are already collecting bug bounties. https://githu…

X AI KOLs Timeline · 2026-06-14 Cached

Introducing Claude-BugHunter, a skill pack designed for Claude Code, containing 71 skills, 15 slash commands, and 681 public report patterns, aiming to transform Claude Code into an advanced bug bounty hunter or red team operator.

0 favorites 0 likes
#bug-bounty

AMD Stiffs Researcher $10k Bug Bounty

Hacker News Top · 2026-06-12 Cached

AMD denied a $10,000 bug bounty to researcher Paul LaRosa after he discovered a critical HTTP vulnerability in AMD's Windows auto-updater, allowing man-in-the-middle attacks; the company took 124 days to fix the issue and still uses weak CRC32 checksums.

0 favorites 0 likes
#bug-bounty

@trybughunter: C̶l̶a̶u̶d̶e̶ ̶B̶u̶g̶ ̶H̶u̶n̶t̶e̶r̶ is now BUG HUNTER. We changed the name because it is no longer limited to Claude Cod…

X AI KOLs Timeline · 2026-06-11 Cached

Claude Bug Hunter has been renamed to BUG HUNTER, a standalone open-source CLI tool that supports multiple AI providers including Ollama, Groq, DeepSeek, Claude, OpenAI, and Grok, designed for the bug bounty community.

0 favorites 0 likes
#bug-bounty

The RCE that AMD wouldn't fix

Hacker News Top · 2026-06-11 Cached

A researcher discovered a remote code execution vulnerability in AMD's AutoUpdate software due to insecure HTTP download links and lack of certificate validation. AMD initially dismissed it as out of scope but later agreed to issue a CVE and fix after public attention.

0 favorites 0 likes
#bug-bounty

Microsoft Threatened Legal Action Against a Security Researcher. The Security Community Pushed Back.

Reddit r/ArtificialInteligence · 2026-05-29 Cached

A security researcher published six unpatched Windows zero-day vulnerabilities, including working exploit code, without Microsoft's knowledge. Microsoft threatened legal action and criminal referrals, drawing widespread criticism from the cybersecurity community over its handling of the situation.

0 favorites 0 likes
#bug-bounty

The pressure

Lobsters Hottest · 2026-05-26 Cached

Daniel Stenberg reflects on the pressure of maintaining the curl open-source project, discussing the relentless work on security, scrutiny, and the impact of AI-generated bug reports.

0 favorites 0 likes
#bug-bounty

The AI Era Is Creating a Bug Hunting Arms Race

Wired · 2026-05-25 Cached

The article explores how AI-powered bug hunting is flooding vulnerability disclosure programs, changing the economics of bug bounties, and compressing disclosure timelines, while also benefiting attackers.

0 favorites 0 likes
#bug-bounty

Claude Mythos Preview Finds 10,000+ Critical Software Flaws With 50 Partners: Anthropic

Reddit r/ArtificialInteligence · 2026-05-23 Cached

Anthropic's Claude Mythos Preview model, used by 50 partners, has uncovered over 10,000 high- and critical-severity software vulnerabilities, including 2,000 bugs in Cloudflare's systems and a critical flaw in wolfSSL, signaling a paradigm shift in software security.

0 favorites 0 likes
#bug-bounty

The Wonders of AI: We Are Retiring Our Bug Bounty Program

Hacker News Top · 2026-05-15 Cached

Turso is retiring its bug bounty program due to an overwhelming influx of low-quality, AI-generated submissions, highlighting the growing challenge of AI slop in open source maintenance.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback