Validated vulnerability is half the work.
Another half is the surrounding context: how the vendor reacts to the report, how much silence lasts, and if the public record ever gets updated about something already known.
I had two such cycles in a relatively close proximity.
One ended up published on Anthropic's public Hacktivity feed after several months. The report was a security-mechanism bypass in the implicit trust boundary within the product surface, not a scanner hit. I used an LLM as a sparring partner to test the initial threat model and then exploited the assumption that seemed to be the most affordable to check. Acceptance and retest mattered more than public writeup at this time.
The second cycle worked vice versa. After a prolonged silence regarding an important report against an AI flagship gateway, I decided to coordinate disclosure through CERT/CC. Uncoordinated public disclosure is a last resort, not a growth hacking move. A coordinator exists for a certain purpose – in case the vendor doesn't accept even a P1 vulnerability.
Some things I can't stop thinking about:
1. AI products have the same weaknesses as web applications of old: trust boundaries, UI state, and "this parameter is only for us".
2. Volume programs suffer from information overload. 3,300 reports in 90 days with a small subset of valid ones is not an achievement. This is a filter issue.
3. AI auditing of AI is helpful when it allows you to argue with the design and not when it generates payloads.
4. Public metadata is not full disclosure. Public metadata is a proof that the work was done.
Still no payloads and technical details to share. This is the whole point of doing this the right way.
If you do any work with AI gateways, agent UIs, or bug bounties for such platforms, I am curious how you define "implicit trust" vs "intended behavior". DMs are open.
#BugBounty #AISecurity #ResponsibleDisclosure #GenAI #OffensiveSecurity
That “100 phones in a car” hack is just the loud version.
Same ranking signals.
Quieter implementation: Android that isn’t a phone in a van.
I filed the integrity-side issue.
Status: Won’t Fix (Infeasible). Translation: fix is too hard / too breaking right now. Then they reused the ticket anyway.
That “100 phones in a car” hack is just the loud version.
Same ranking signals.
Quieter implementation: Android that isn’t a phone in a van.
I filed the integrity-side issue. Status: Won’t Fix (Infeasible). Translation: fix is too hard / too breaking right now.
Then they reused the ticket anyway.
#android #google ##BugBounty
WHY IS THIS GUY DRIVING AROUND WITH 100s OF PHONES IN HIS CAR?
Well, apparently, this is a shady but effective local SEO hack lol
“Google has a patent describing directions-based ranking of places. It explicitly describes using direction requests and mobile location/search logs as signals of a place's popularity.”
So now, there are literal services like this where they drive around with 100s of phones to your local business...
Indicating your business is in demand, and this will apparently boost your local ranking
can’t wait to see what Google will do about this
A valid bug I reported against https://t.co/zMklXFdn6v just showed up on Anthropic’s public HackerOne Hacktivity feed.
I submitted it about six months ago. Took a while, but the metadata is public now.
These programs are brutal to work. Anthropic got 3,300+ reports in the last 90 days and has only resolved 327 valid ones for the entire program. A lot of that queue is noise. Scanners don’t help much here. You have to actually sit with how the product is built and look for the assumptions nobody questioned.
That’s what this one was. I used an LLM as a sparring partner to think through the threat model, then went after an implicit trust issue. It came back as a validated Security Mechanism Bypass: UI redress through a ?fullscreen parameter on https://t.co/zMklXFdn6v.
I’ve been doing more of this lately - using AI to audit AI. It works better than I expected.
I can’t share the payloads or the full write-up. Still under responsible disclosure. Getting it accepted and through retest was enough for me.
If you’re working on AI product security or dealing with trust boundaries in these systems, I’m around. DMs are open.
Hacktivity: https://t.co/5B2YzGXeDI
Profile: https://t.co/1b97MyveLl
#BugBounty #Anthropic #GenAI #OffensiveSecurity #AIResearch #CyberSecurity
My biggest #BugBounty win? A $0 invoice.
I reported a core Android flaw. Google closed it as "Won't Fix" to save legacy devices. Months later, they resurrected my ticket to shape their next-gen security architecture.
Impact isn't always a check.🚀 #CyberSecurity#AndroidSecurity
🚨 BREAKING: I just initiated uncoordinated public disclosure via CERT/CC (Tracking VRF#26-08-ZLWZB) against $128B AI giant https://t.co/PvXzsaALzN After a systematic 97-day communication blackout regarding a Critical P1 vulnerability on their flagship gateway
@lmncode