Maybe watch the codebase next time? Threatening researchers instead of patching is how you guarantee the next finder just sells it instead of reporting it.
Cyber security agencies of the Govt of India, such as the Indian Cybercrime Coordination Centre (I4C), etc., are keeping a close watch on the cyber attacks on the CBSE OSM reevaluation portal. Strict penal action will be taken against the perpetrators - Education Ministry sources to ANI
@_godiego__@Bugcrowd Just BC thing:
First response -> NMI, need proper steps
Me - Everything is in the report, nothing to add
Second Response - Triaged
AI isn't replacing bug bounty hunters. It's replacing the gap between you and a seasoned hacker: the mentor you don't have, the writeup you can't find, the code review you can't get. If you use it right.
New video on exactly how: https://t.co/65HkPgr7UZ
Needle in the haystack: LLMs for vulnerability research
I've distilled my experience of sending thousands and thousands of prompts for using LLMs to discover vulnerabilities into a single write-up.
These are the conclusions I came to..
(link in comment)
‼️ The axios lead maintainer has gone public on how he was socially engineered into installing the malware behind the npm supply chain attack.
We have example images showing exactly how the attack was staged.