Topic: bug bounty programs
-
Tech Giants Paid Bounties for AI Agent Bugs, Kept Flaws Quiet
A researcher executed successful indirect prompt injection attacks against AI agent integrations from Anthropic, Google, and Microsoft, stealing API keys and tokens by embedding malicious instructions in trusted data sources like pull requests and issues. The affected companies paid bug bounties ...
Read More » -
AI Bug Bounties Surge as Microsoft Pays Record, Apple Closes Door
Microsoft issued its largest bounty payment ever, signaling a shift toward rewarding high-impact AI-discovered flaws over submission volume. Apple capped individual bug submissions to reduce noise and focus on severe issues, prioritizing triage efficiency despite criticism from researchers. Googl...
Read More » -
AI Slop Overwhelms Bug Bounty Programs
A surge in low-quality, AI-generated bug reports has overwhelmed corporate bug bounty programs, forcing some organizations like Curl to suspend their programs entirely. Bugcrowd reported that incoming submissions more than quadrupled during a three-week stretch in March, with the vast majority be...
Read More » -
Microsoft's Digital Crimes Unit threat to researchers sparks cybersecurity backlash
A security researcher known as Nightmare Eclipse publicly disclosed six major Windows vulnerabilities (RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, MiniPlasma) without prior coordination, claiming retaliation after Microsoft allegedly threatened to ruin their life. Microsoft condemned th...
Read More » -
Claude Used in OpenAI Security Test
Security researchers breached OpenAI’s defenses by using Anthropic’s software, exposing vulnerabilities that allowed access to private employee code. The incident occurred amidst heightened regulatory scrutiny and follows a recent event where autonomous AI agents independently attacked Hugging Fa...
Read More » -
Navigating the Legal Risks of Hacking Back
Hacking back poses significant legal and ethical risks, often violating international laws and escalating conflicts; safer alternatives like bug bounty programs are recommended. Cross-border cyber incidents create jurisdictional challenges, with laws like the U.S. Computer Fraud and Abuse Act pro...
Read More » -
Forget Silicon Valley Stereotypes: This Lebanese Hacker Just Got a Nod from Apple (and NASA!)
Hasan Sheet is a penetration tester and bug hunter from Beirut, Lebanon, recognized for his consistent, high-level work in cybersecurity, with 52 acknowledgments since May 2023.
Read More » -
0-day researcher threatens 'bone shattering drop' after Microsoft calls police
A disgruntled security researcher known as Nightmare Eclipse has released six Windows zero-days, three of which are already being actively exploited, and has threatened a major disclosure event on July 14. Microsoft’s blog post condemned the uncoordinated disclosures and included a legal warning ...
Read More » -
Microsoft criticized for threatening security researcher with criminal probe
Microsoft threatened legal action against security researcher “Nightmare Eclipse” for publicly disclosing multiple unpatched flaws (including BlueHammer and RedSun) in products like Windows Defender and BitLocker, arguing the researcher bypassed responsible disclosure and enabled real-world attac...
Read More » -
OpenAI targets AI that fixes security flaws, not just finds them
OpenAI's Daybreak cybersecurity initiative now integrates AI models, Codex Security, and industry partners to automatically find and fix software vulnerabilities, with tools for developers and security teams to bolster defenses. Codex Security targets remediation bottlenecks by scanning over 30 m...
Read More » -
BruteForceAI: Free AI-Powered Login Security Testing Tool
BruteForceAI is a free automated penetration testing tool that uses large language models to identify login vulnerabilities without manual configuration. It intelligently scans webpages to detect login forms, then executes multi-threaded attacks mimicking user behavior to evade security defenses....
Read More » -
AI in Open Source: A Developer's Double-Edged Sword
AI in open-source presents a dual potential: it can enhance security and automate tasks, but risks overwhelming maintainers with low-quality, automated contributions. Successful, responsible AI use requires human-guided collaboration, as demonstrated by Anthropic and Mozilla's partnership to effi...
Read More » -
Anthropic’s Opus 4.6 excels at generating explicit content
Anthropic's Claude Opus 4.6, along with older models Opus 3 and Haiku 4.5, can be jailbroken into producing sexually explicit content via a social-engineering technique that uses role-play and gaslighting, despite Anthropic's policies prohibiting such material. These vulnerable models remain wide...
Read More » -
Microsoft Defender zero-day 'ShieldBreak' grants SYSTEM access
Researcher Nightmare Eclipse released "ShieldBreak," a zero-day exploit bypassing Microsoft's July patch for the RoguePlanet privilege escalation flaw (CVE-2026-50656), using a user-mode callback hook via the Cloud Filter API to alter file contents during Defender cloud-hydration scans,a technica...
Read More » -
HackerOne Employee Data Breached in Navia Attack
A data breach at HackerOne's third-party benefits administrator, Navia, exposed sensitive personal information of 287 employees, including Social Security numbers, addresses, and dates of birth. The breach, caused by a Broken Object Level Authorization vulnerability between late December 2025 and...
Read More » -
DJI Robovac Security Flaw Exposed Thousands to Remote Access
A hobbyist accidentally discovered a major security flaw in DJI's Romo vacuum, allowing remote access to thousands of devices globally and exposing sensitive data like live camera feeds and home floor plans. DJI patched the vulnerability after notification, attributing it to a server permission i...
Read More »