#bug-bounty
Sesam veröffentlicht den Quellcode seiner neuen Wahl- und Abstimmungssoftware. Sicherheitsforschende können die Lösung nun öffentlich auf Schwachstellen prüfen.
Sesam öffnet Wahlsoftware für Security-Forschende
Die Zürcher Firma veröffentlicht den Quellcode ihres Wahl- und Abstimmungssystems Sesamvote und startet ein öffentliches Bug-Bounty-Programm.
www.inside-it.ch
September 29, 2026 at 1:17 PM
I just completed LLM Security room on TryHackMe! Wrapping my head around #LLM #vulnerabilities perfectly bridges my bug bounty and detection mindsets, natural language is the new execution vector.
tryhackme.com/room/llmsecu...

#tryhackme
tryhackme.com
September 29, 2026 at 12:45 PM
Real findings need real proof.

Sony publicly acknowledged that Specter, our autonomous pentesting engine, found an important vulnerability through their HackerOne bug bounty program. 🧵
September 29, 2026 at 11:43 AM
Going From Bug Bounty Bugs to More Secure Systems

This article frames aisy as a superior solution by focusing heavily on process optimization through AI agents, but it overlooks the foundational problem of identifying *which* identity risks are most critical for immediate mitigation versus long…
huntaegis.com
September 29, 2026 at 9:30 AM
Automating my security workflow!
Connected Viktor (AI coworker) with security platforms like HackenProof to auto-track vulnerability reports and streamline bug bounty management right inside Slack.
Try it out and boost your productivity here:
🔗 ref.viktor.com/cfZeNtX
#AI #Web3Security #BugBounty
Viktor | Not a tool. A hire.
Viktor is the AI employee that lives in Slack and Microsoft Teams, connects to 3,200+ tools, and does the work. Reports, dashboards, code, campaigns. Start free.
ref.viktor.com
September 29, 2026 at 9:29 AM
bugbounty-lab101 — A complete bug bounty workspace for HackerOne researchers. Includes scope enforcement, automated recon/vuln pipeline (400+ tools), report templates, CVE/CWE watchlists, and a local VM practice lab. Built for disciplined, ethical hunting. https://ktp.sh/F5aJ67yVQ6
September 29, 2026 at 9:12 AM
BTSE bug bounty on HackenProof: Critical $2,000-$3,000, High $700-$1,500. Scope: trading, wallet, API. https://hackenproof.com/programs/btse-bug-bounty-program Follow for grants, credits, and bounty updates each day.
Rewards Range of bounty$100 - $3,000 Severity Critical$2,000 - $3,000 High$700 - $1,500 Medium$300 - $500 Low$100 - $200
bounty upside
hackenproof.com
September 29, 2026 at 9:03 AM
Now there may be some meta-heads in the crowd that are like "but what about Sentinel and all the external monitoring stuff that should watch malicious botnets and blah blah blah." that's an interesting system in itself, but i plan on submitting a few more bug bounty reports in the next few days […]
Original post on neuromatch.social
neuromatch.social
September 29, 2026 at 8:21 AM
RE: https://neuromatch.social/@jonny/117339825958098508

OK! Meta evaluated this as intended behavior, not applicable for a bug bounty, so therefore responsible disclosure no longer applies so here goes:

any process run within the VM can access the socket that provides inference with no […]
September 29, 2026 at 5:22 AM
Relay Protocol hit by API vulnerability, causing "sandwich attacks" on users. ~$136K profit for attackers, 5.6K users affected with median loss of ~$11.88. Relay will fully compensate all users (~$312K total) directly. Bug bounty paid to Outputlayer. #blockchain #security #crypto
September 29, 2026 at 2:21 AM
Teenager hacks open Microsoft database with 17 trillion total rows and 25,000 user accounts — custom AI bot and lack of JWT token validation yields a fruitful trove, earns $5,000 bug bounty
Teenager hacks open Microsoft database with 17 trillion total rows and 25,000 user accounts — custom AI bot and lack of JWT token validation yields a fruitful trove, earns $5,000 bug bounty
www.tomshardware.com
September 29, 2026 at 2:00 AM
🤖 A teenager exploited a Microsoft database with 17 trillion rows and 25,000 accounts, earning a $5,000 bounty.
Wow, who knew coding could be this lucrative? Like, *if only* we had that kind of access in our day... 🤔 https://gigcitygeek.com/306129
Teenager hacks open Microsoft database with 17 trillion total rows and 25,000 user accounts — custom AI bot and lack of JWT token validation yields a fruitful trove, earns $5,000 bug bounty | Tom's Hardware
I guess that purely technically, the JWT token authorization was there.
gigcitygeek.com
September 29, 2026 at 12:31 AM
Cybersecurity alert: The npm package tw-pkgprobe-7731, uploaded in Aug 2026 by twdepprobe7731, pretends to be a Twilio security tool but secretly harvests sensitive data. Stay vigilant!
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Malicious npm package tw-pkgprobe-7731 targets Twilio developer environments and can exfiltrate credentials and environment data.
thehackernews.com
September 28, 2026 at 11:33 PM
𝗠𝗮𝗹𝗶𝗰𝗶𝗼𝘂𝘀 𝗻𝗽𝗺 𝗣𝗮𝗰𝗸𝗮𝗴𝗲 𝗣𝗼𝘀𝗲𝘀 𝗮𝘀 𝗧𝘄𝗶𝗹𝗶𝗼 𝗕𝘂𝗴-𝗕𝗼𝘂𝗻𝘁𝘆 𝗣𝗿𝗼𝗯𝗲, 𝗖𝗮𝗻 𝗘𝘅𝗳𝗶𝗹𝘁𝗿𝗮𝘁𝗲 𝗖𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹𝘀
Cyber...
https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html
Call us for a FREE IT Assessment! (888) 999-2709
September 28, 2026 at 9:51 PM
📢 Cloudflare corrige une vulnérabilité d'exposition de données inter-tenants dans Containers

Cet article constitue un post-mortem détaillé d'une vulnérabilité de type cross-tenant data exposure affectant Cloudflare…

🟡 vérification factuelle moyenne
#CloudflareContainers #BugBounty #Cyberveille
Cloudflare corrige une vulnérabilité d'exposition de données inter-tenants dans Containers
Cet article constitue un post-mortem détaillé d'une vulnérabilité de type cross-tenant data exposure affectant Cloudflare Containers et Cloudflare Sandboxes. La vulnérabilité a été signalée de manière responsable le 4 septembre 2026 par Oren Yomtov, chercheur en sécurité chez Accomplish, via le programme de bug bounty HackerOne de Cloudflare.
cyberveille.ch
September 28, 2026 at 9:30 PM
Um CORNO vibecodou um fork do Onion e tá pagando 20 dólares pra quem trabalhar mais por ele achando bugs. É muita cara de pau.

E ninguém nos comentários apontando a canalhice
September 28, 2026 at 7:33 PM
For no particular reason, say you found a vulnerability in a piece of software. This developers of this software claim that a bunch of things that would normally be considered vulnerabilities are actually intended behavior, but this is still beyond that and definitely in their bug bounty list […]
Original post on neuromatch.social
neuromatch.social
September 28, 2026 at 7:06 PM
Beat one of the Bug Fable Plus new bounty bosses.

They don't play.

They also have good music.
September 28, 2026 at 6:48 PM
The Vercel Bug Bounty Program is now publicly available | Vercel News
The Vercel Bug Bounty Program is now publicly available
Vercel's Bug Bounty Program is now public on HackerOne, covering all Vercel products and open-source projects. Learn how to participate and report findings.
vercel.com
September 28, 2026 at 6:15 PM
himself from yelling out and waking his parents at 2 am.

After reporting the problem to Microsoft's bug bounty program, he was awarded with $5,000 for his findings. In his blog post, he also points out that "AI and human intuition compounded here. Antares did ten days of work I
September 28, 2026 at 4:20 PM
A teenager hacked a Microsoft database containing 17 trillion total rows and 25,000 user accounts using an AI orchestrator bot named Antares.

Source: Tom's Hardware
Teenager hacks open Microsoft database with 17 trillion total rows and 25,000 user accounts — custom AI bot and lack of JWT token validation yields a fruitful trove, earns $5,000 bug bounty
I guess that purely technically, the JWT token authorization was there.
www.tomshardware.com
September 28, 2026 at 11:42 AM
Teenager hacks open Microsoft database with 17 trillion total rows and 25,000 user accounts — custom AI bot and lack of JWT token validation yields a fruitful trove, earns $5,000 bug bounty
I guess that purely technically, the JWT token authorization was there.

www.tomshardware.com/tech-industr...
Teenager hacks open Microsoft database with 17 trillion total rows and 25,000 user accounts — custom AI bot and lack of JWT token validation yields a fruitful trove, earns $5,000 bug bounty
I guess that purely technically, the JWT token authorization was there.
www.tomshardware.com
September 28, 2026 at 11:37 AM