Tag
A researcher discovered a remote code execution vulnerability in AMD's AutoUpdate software due to insecure HTTP download links and lack of certificate validation. AMD initially dismissed it as out of scope but later agreed to issue a CVE and fix after public attention.
A security researcher published six unpatched Windows zero-day vulnerabilities, including working exploit code, without Microsoft's knowledge. Microsoft threatened legal action and criminal referrals, drawing widespread criticism from the cybersecurity community over its handling of the situation.
Daniel Stenberg reflects on the pressure of maintaining the curl open-source project, discussing the relentless work on security, scrutiny, and the impact of AI-generated bug reports.
The article explores how AI-powered bug hunting is flooding vulnerability disclosure programs, changing the economics of bug bounties, and compressing disclosure timelines, while also benefiting attackers.
Anthropic's Claude Mythos Preview model, used by 50 partners, has uncovered over 10,000 high- and critical-severity software vulnerabilities, including 2,000 bugs in Cloudflare's systems and a critical flaw in wolfSSL, signaling a paradigm shift in software security.
Turso is retiring its bug bounty program due to an overwhelming influx of low-quality, AI-generated submissions, highlighting the growing challenge of AI slop in open source maintenance.
BugTraceAI releases CORE-Ultra-27B-Q6, a specialized tooling model built on Qwen3.6-27B and fine-tuned on 2,541 real-world security reports, designed to generate complete, executable artifacts like Nuclei templates and CVE PoCs.
Anthropic has made its private security bug bounty program public on HackerOne, allowing anyone to report vulnerabilities and receive rewards.
OpenAI has launched a Bio Bug Bounty program for GPT-5.5, inviting security researchers to identify universal jailbreaks for biological safety challenges. The program offers rewards up to $25,000 for successfully defeating the model's safeguards on specific bio-risk questions.
OpenAI is launching a public Safety Bug Bounty program focused on identifying AI abuse and safety risks — including agentic risks, MCP vulnerabilities, and account integrity issues — complementing its existing Security Bug Bounty program. Researchers can submit issues that pose meaningful safety risks even if they don't qualify as traditional security vulnerabilities.
This article discusses how AI-generated code and agentic AI are overwhelming open source maintainers with low-quality pull requests and bug reports, causing projects like curl to drop bug bounties and leading to harassment of maintainers.
OpenAI has launched a bio bug bounty program inviting vetted researchers to find universal jailbreaks in ChatGPT Agent's bio/chem safety challenge, offering up to $25,000 for a successful universal jailbreak across all ten levels. Applications open July 17, 2025, with testing beginning July 29, 2025.
OpenAI has launched a Bug Bounty Program in partnership with Bugcrowd, offering cash rewards ranging from $200 to $20,000 for security researchers who discover and report vulnerabilities in OpenAI's systems.