Tag
A veteran bug bounty hunter reflects on HackerOne's evolution from its golden age of live hacking events to its current state, questioning what changed and whether the platform still serves its original hacker-first mission.
GitHub is restructuring its bug bounty program to prioritize quality over quantity, introducing a permanent VIP program with higher payouts, restructured public bounties with static payouts, and raising signal requirements to reduce low-effort reports.
The user tested Grok 4.5's security penetration capabilities and found that it could autonomously log into HackerOne, scan over 400 projects, and perform bug hunting, with almost no human involvement throughout, demonstrating powerful automation capabilities.
Hyunseo Shin, Korea's #1 HackerOne hacker, shares a follow-up post detailing his AI-based vulnerability detection workflow using LLM agents to uncover open-source 0-days.
Anthropic has made its private security bug bounty program public on HackerOne, allowing anyone to report vulnerabilities and receive rewards.