@wunderwuzzi23 That's awesome, man seriously, the biggest bounty I have seen for an AI bug. You must be the person behind the AI 2FA bypass bug on instagram 👀
@BugBountyDEFCON@hackthebox_eu@PentesterLab I am preparing for the HTB CWEE exam, and by winning the HackBox annual license, I can broaden my knowledge across various domains, such as hardware, mobile which will help in doing security research.
Time for another giveaway!
We will pick 6 winners to win one of the following:
1x Annual VIP @hackthebox_eu Licence
5x @PentesterLab 3 Month Licences
To enter:
1️⃣ Follow us @BugBountyDefcon
2️⃣ Like this post ❤️
3️⃣ Re-tweet this post 🔁
Giveaway open until Monday June 15th! GOOD LUCK!
@rez0__ I think maybe the company must have closed the program, as I saw a few days ago someone got a bounty from Huntr. After Palo Alto acquired it last year, has something changed?
Not everyone who reports to Google Cloud VRP does a writeup, but critical bugs still show up in CVEs and release notes
Made a tool that aggregates both so you can see the types of bugs getting found in GCP
https://t.co/S8C6q67r2N
@bug_vs_me For me it worked after starting a new session if it's not working for you then reachout to claude support and it happens their cyber use case is not bulletproof.
I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer!
The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below:
https://t.co/nY20Anz0VO
(and thanks @garethheyes for making Shazzer!)
@ITSecurityguard You are right, Patrik. If a top researcher like @infosec_au is facing this issue, what about normal researchers who work hard every day to submit a report, in the hope that the platform will see their report, but they removed the human part that acted as a bridge for both.
@_jensec You are right, dude. Seriously, the wait time is so long that after a certain period of time, it leads to less motivation. If platforms can't handle it, then it's better they acknowledge it publicly and ask for public feedback to improve it. Many programs are closing duetoAI slop
AI will kill bug bounties NOT because it’s better than human hunters.
It’ll kill them because platforms are failing at handing triage queues and unable to distinguish legit bugs from AI Slops.