Platforms using our reports to train their AI and sell products to clients, platforms not being fair/transparent in LHE invitations, our future is bright comrades! I hope someone can learn a thing or two. The change is now.
I’m once again here to tell you that *most* bug bounty platforms will or have used your hunting data in AI endeavors.
bug bounty as an enterprise strategy is much lower margin than AI security.
Or they will use it for auto triage. Which then they will conveniently forget those models were trained on hunter data and transition those models to discovery.
Also. Be wary of specific wording / terminology . They may not train a model with the data, but they may take the tools and techniques and use their engineering teams to turn those into automations that the AI will fire and scale.
https://t.co/n6VYvNzJsl
so the bug bounty community freaked out a few weeks ago when hackerone had a single slide that talked about using AI agents for testing based off our reports. bugcrowd's new strategy sounds even more brazen, sly and egregious.
submit reports -> your "signals" (aka creative thought process and work) feed into their AI agents -> AI agents find bugs without you (unclear incentive structure).
that's if the technology even works though lol. these days I have trouble even adding collaborators in reports without the app erroring out.
the messaging is so much more slick too. "connect those signals" - does that mean they are training on our reports? at least whoever did this PR release was careful to not blatantly say that they are training on our reports.
but lol what does connecting those signals actually mean at the end of the day? extremely unclear if they train on our reports.
this requires actual transparency from both platforms, not just marketing, and messaging tactics that you use when you're trying to convince you're not a wolf in a sheeps clothing.
@Alra3ees Praying for you, brother. Get well soon. I remember the good old days when you used to share valuable resources with the community. Wishing you a successful surgery and a speedy recovery.😊
I'm not sure the community will like this. @Hacker0x01 will now reuse your novel techniques / exploits / old reports to look for vulns on the rest of the customer's infra. I guess they will add you as collab and give you a bounty, right? right?!
can we get more context on this @Hacker0x01@senorarroz ? :D
(if anyone wants to read it, it's under 'map your attack surface' on https://t.co/Y7TSK1eihP)
HackerOne already stole all the researchers’ reports to build their AI agent, while they keep lying to us.
they’re openly bragging about using 12+ years of real-world vulnerability data + your prior H1 Bounty findings to train their Hai agentic AI system.
They built specialized recon, scanning, and exploit agents that follow the exact same workflow real researchers use at machine scale. All that knowledge researchers poured into the platform for years? Now it’s powering their proprietary AI product.
And they still act like they’re the good guys protecting the hacker community.
Fuck HackerOne.
Stop feeding the machine that’s going to replace you.
https://t.co/mVYS6bEXyk
* Create your own AI scanner
* Create website for that AI
* Offer it for Sale/Subscription
* create a X profile for the AI
* Start Posting Old bounty’s photos with posts like (found this by this @AI, I spend 10$ and I got rewarded 10K$)
Story Of This Days 😤
Not #bugbouny 🫣