I can't stress it enough when I say I would rather commit ritualistic japanese suicide and die a warriors death than sit around training bug bounty platforms to automate me out of the pipeline with my bug reports
@CaleAnderson02 How much enthusiasm do you think there would be on the H1 side? We can herd the cats in crypto to make something happen, but I'm wondering if there would be real interest.
As far as I've seen, only Immunefi has had the will to strengthen the SR's hand and treatment at scale.
@MitchellAmador There’s a solid group of current / ex h1 triagers that would jump at the opportunity to handle this. Will dm and can make some intros 🫡
Alright,
A few thoughts on the triage discussion.
Everyone is talking about AI slop, but I think it’s exposing a bigger issue that’s existed for years.
Bug bounty still doesn’t have shared standards for triage or mediation.
The same report can receive completely different outcomes depending on the platform, customer, triager or mediator involved.
That was frustrating when report volume was manageable.
1/?
Personally I’d love to see two open standards emerge.
A triage standard maintained by HackerOne since they have the strongest technical team out of any platform (I’m biased here)
A mediation standard maintained by Immunefi since they seem to handle it the best
Not owned by them. Maintained by them. And adopted by every platform
Put both in public GitHub repositories. Let hackers, customers and platforms propose changes, discuss them publicly and vote on them.
If AI is going to increase report volume by 10x or 100x, the least we can do is make sure that we have clear consistent standards across every platform
The goal should be to make bug bounty more consistent, transparent and scalable before AI forces the issue for everyone.
3/3
We have CVEs.
We have CWEs.
We have CVSS.
We don’t have an equivalent standard for how reports are triaged, how duplicates are handled, how impact is assessed, how mediation works or what happens when there is a dispute.
Instead every platform and customer has their own interpretation of the rules.
2/3
$1,000 Hack The Box Labs Giveaway
10 winners | $100 giftcard each
To enter: follow @vxgiveaways and @ObvaneGroup, then comment below sharing why you'd like to win
Winners picked in a week
We Googled a shipping label file format.
Less than an hour later, we had domain credentials.
New research from Obvane on .nlbl weaponization and an overlooked enterprise attack surface.
https://t.co/IL2IP9vgL4
Russian Market reads less like a forum and more like a storefront with felonies.
Obvane looks inside one of the largest criminal marketplaces online and the economy that formed around it.
https://t.co/ozyEBOZWZ4
🤖 65% of Forbes AI 50 companies leaked secrets on GitHub. @sshaybbc revealed how AI speed without security = leaks waiting to happen.
Full Wiz Research report 👉
https://t.co/kmamDrkIo3
Reverse engineering tip
If you're not sure something is ransomware, run it as Admin on your computer
If your documents are no longer accessible and your wallpaper has changed, then it is probably ransomware
@Steam You clowns allow malware on your platform that has resulted in $150K+ stolen from victims (fake game has been available to download for more than a month)
wow... great finds. good writeup, worth a read! :) and if you've ever been to burgerking drivethru, AI is analyzing your convos ;D https://t.co/5KPuLFMml8