I think the biggest problem in bug bounty today is the platforms themselves. Filtering spam reports only treats the symptoms, not the root cause. Platforms should educate hunters on what actually qualifies as a security vulnerability.
Also, bug bounty platforms shouldn’t focus on building their own AI scanners. They should help hunters use AI more effectively by providing better tools, workflows, and guidance.
If someone repeatedly submits spam, temporarily restrict submissions until they complete training or pass an assessment. Build a shared standard for report quality.
See how Chinese red-team / pen-testers see China's e-government infrastructure and witness how they assess security flaws in the govt run service infrastructure ( has diagrams and pictures ) : https://t.co/oncjuBZ162
XBOW automatically runs expert-level attacks across all webapps, giving security teams unprecedented scale.
@XBOW reported 1092 vulnerabilities on HackerOne in just a few months, including RCE, XXE, SQLi, SSRF, exposed secrets, and XSS.
Fantastic! Ho Xuan Ninh (@Xuanninh1412) and Tri Dang (@trichimtrich) from Qrious Secure successfully demonstrated their exploit of #NVIDIA Triton. Will it be unique or another bug collision? They are off to the disclosure room to find out. #Pwn2Own#P2OBerlin
The Bybit hack is officially the largest crypto heist in HISTORY.
$1.46B+ stolen and still counting. That's 16% of ALL previous crypto hacks COMBINED.
Here's what happened, what we know, and why this could change everything 🧵👇
The hack, what the Treasury called a "major incident", happened in December when Chinese state-sponsored hackers breached the department's computer security guardrails by compromising third-party cybersecurity service provider BeyondTrust.
Read more: https://t.co/pb2UyIvg3c
@adnanthekhan@msftsecresponse bro, you should focus on their products, not their internal or infra assets. their program scope indeed need to be improved.