@AhmedMa07846126@Hostinger Mine was due to a recon script firing too fast and triggering a network traffic abuse. So I implemented a rate limit on the outbound traffic to mitigate the issue. Once i provided the root cause and mitigation plan they un-banned me.
@Hostinger Hi, yes I will send a DM, I have also sent an email to your compliance team, with more details of my work, LinkedIn profile, and researches i have completed in the past.
Two days ago the US banned Claude Fable 5.
Yesterday China dropped GLM 5.2.
Today GLM 5.2 is #1 on @bridgebench BS at 100.0, and #1 on Reasoning at 42.8, beating Fable 5.
At 1/10th the cost and 300 tokens per second.
You cannot export control your way out of an open source race.
The ban didn't slow China down.
Unban Fable 5.
I’m once again here to tell you that *most* bug bounty platforms will or have used your hunting data in AI endeavors.
bug bounty as an enterprise strategy is much lower margin than AI security.
Or they will use it for auto triage. Which then they will conveniently forget those models were trained on hunter data and transition those models to discovery.
Also. Be wary of specific wording / terminology . They may not train a model with the data, but they may take the tools and techniques and use their engineering teams to turn those into automations that the AI will fire and scale.
https://t.co/n6VYvNzJsl
so the bug bounty community freaked out a few weeks ago when hackerone had a single slide that talked about using AI agents for testing based off our reports. bugcrowd's new strategy sounds even more brazen, sly and egregious.
submit reports -> your "signals" (aka creative thought process and work) feed into their AI agents -> AI agents find bugs without you (unclear incentive structure).
that's if the technology even works though lol. these days I have trouble even adding collaborators in reports without the app erroring out.
the messaging is so much more slick too. "connect those signals" - does that mean they are training on our reports? at least whoever did this PR release was careful to not blatantly say that they are training on our reports.
but lol what does connecting those signals actually mean at the end of the day? extremely unclear if they train on our reports.
this requires actual transparency from both platforms, not just marketing, and messaging tactics that you use when you're trying to convince you're not a wolf in a sheeps clothing.