An incredible week of creativity, collaboration, and impact from the global security researcher community. Alongside @PayPal, you showed up and delivered.
The work at this event helps keep customer data safe. Congrats to our winners:
MVHs: alexbirsan, 82af5ddffbb795
Exterminator: ahacker1
Eradicator: oag
Eliminators: alexbirsan, 82af5ddffbb795
#H1030 #TogetherWeHitHarder
🎉 Congratulations to Shrimant More!
Today we're recognizing Shrimant More from the HackerOne India West Club as our Brand Ambassador of the Quarter.
Through impactful community events, mentorship, and a commitment to strengthening connections across the global security researcher community, Shrimant continues to make a lasting impact both locally and around the world.
HackerOne's Brand Ambassador of the Quarter recipients are recognized for their ability to:
🌍 Represent their region while fostering global collaboration
🗓️ Organize events, workshops, and meetups that educate and inspire the community
🚀 Create meaningful impact by growing and strengthening local and global security researcher communities
Thank you, Shrimant, for your leadership, dedication, and passion for bringing the community together. We're proud to celebrate the people helping make the internet safer, one connection at a time.
#TogetherWeHitHarder
Learn more about the Brand Ambassador Program: https://t.co/5HfnPU5lQt
Agents can now exploit vulnerable sandbox boundaries, so we are testing ours in the open.
$1,000,000 hacker challenge for Vercel Sandbox:
• Escape the Firecracker microVM
• Defeat the host-side network boundary
• Up to $50k/report via @Hacker0x01
https://t.co/6l4HL845jc
That's a wrap on H1-030 in Berlin.
When the world's best security researchers come together, great things happen for everyone.
Thank you, @PayPal, for the partnership. One mission. Keep the internet safe.
You don’t have to be at the event to be part of the program. Check out how to get involved in PayPal's public program here: https://t.co/vnyPzOjog9
That’s a wrap on #DEFCON!
Huge thanks to @BugBountyDEFCON and everyone who stopped to meet, chat, and spend time with us this week.
And seeing the H1 logo light up on this year’s badge? Yeah, we loved that. 💖
Until next time, Vegas!
Yesterday at #DEFCON, Shrimant More and Martzen Haagsma shared what happens when you run a bug bounty program on your own bug bounty platform.
Every report from the security researcher community puts our product, workflows, and assumptions to the test.
Sometimes a small bug teaches a platform-wide lesson. That’s exactly the point. 🔥
Day 1 of #DEFCON is down! 🔥
HackerOne’s Dane Sherrets joined “The Future of Bug Bounty: Program Managers’ Perspective,” while Tony Lee took the stage for “Navigating AI-Assisted Submissions.”
Great conversations, sharp perspectives, and plenty more ahead. Bring on Day 2.
HackerOne is proud to be a sponsor of the Bug Bounty Village at DEFCON.
Some of our awesome SMEs will be speaking during the event:
- Dane Sherrets, Security Architect, Emerging Technology, will be moderating The Future of Bug Bounty Program Manager Perspective
- Martzen Haagsma, Security Engineer IV and Shrimant More, Senior Security Analyst will present Eating Our Own Dogfood: Running a Bug Bounty Program on a Bug Bounty Platform
- Tony Lee will be a panelist on Navigating AI-Assisted Submissions
Check out what else is going on at the Bug Bounty Village https://t.co/NaIs6iWLmv
What started as a way to catch issues evolved into something bigger. Researcher findings now feed back into how Temu builds products — before anything reaches testing.
Reactive → preventive. That's the shift.
⏰ One week to go.
If you're heading to DEF CON, make plans to join us at the Hacker Hangout with @tiktok_us and @BugBountyDEFCON.
Meet fellow security researchers, grab exclusive swag, and celebrate the community.
📍 Flight Club, Venetian Grand Canal Shoppes
🗓️ Thurs. Aug. 6 | 6–9 PM
RSVP 👇
https://t.co/KfHo1biTxM
If you're heading to DEF CON, don't miss this one.
Join HackerOne, @tiktok_us, and @BugBountyDEFCON for an evening of connecting with fellow security researchers, grabbing some exclusive swag, and celebrating the community.
📍 Flight Club, Venetian Grand Canal Shoppes
🗓️ Thurs. Aug. 6 | 6–9 PM
RSVP 👇
https://t.co/KfHo1biTxM
Calling all researchers!
@Trip is launching a limited-time campaign that will pay out 2x the usual reward for any High or Critical severity vulnerabilities in scope.
Severity will be confirmed by our triage team based on our published severity rubric and our standard bounty program rules apply.
Lasts from July 13 to July 29.
Visit the program page for more information and to see how to get started: https://t.co/Inld0K780h
Thanks for all the awesome work you do and happy hacking!
Today, HackerOne joins Project Glasswing, Anthropic's controlled-access program for Claude Mythos 5. We'll use it to harden our own security and evaluate it across the full CTEM workflow, including discovery, validation, prioritization, and remediation.
Two things up front, because researchers will ask.
Your reports are not training data. Vulnerability submissions stay where they belong: with the customer and the researcher who found them.
And AI is not replacing the bounty model. In the first 6 months of this year, researchers earned approximately $47M in bounties through HackerOne, up 25% year-on-year. More AI on offense and defense means more code shipped, more attack surface created, more reports filed, and more bounty work.
What we learn from applying Mythos to HackerOne’s internal scope will be shared with the wider community.
Read the announcement. https://t.co/KC6MNhlj8n