@chrispavlovski@chrispavlovski Multiple vulnerability reports submitted to Rumble have been sitting without validation or response for months. Security researchers are part of protecting the platform—ignoring responsible disclosures is not the standard expected from a public company.
@chrispavlovski Months of pending vulnerability reports with no validation or communication from Rumble. Security researchers help protect the platform, yet the process shows no urgency. A public company should handle security issues with far greater accountability and speed. @chrispavlovski
@chrispavlovski@chrispavlovski@rumblevideo@ric_rac “Multiple vulnerability reports submitted to Rumble have been pending for months with no clear validation or communication. For a publicly traded company reporting earnings, this level of delay in handling security reports is unacceptable.
@chrispavlovski@chrispavlovski Could you check with your SME team! regarding my security reports sent months ago! and never get a validation of them! This need your attention Man
@ric_rac@ric_rac Many security reports submitted to Rumble have been pending for an extended period without clear validation status or timelines. This requires immediate review and transparent communication. Public earnings discipline should be reflected in the security process as well.
@rumblevideo Immediate action is required on multiple pending vulnerability reports submitted to Rumble. These have been awaiting validation and clear feedback for an extended period. @chrispavlovski@rumblevideo
@rumblevideo Several vulnerability reports submitted to @rumblevideo remain pending without clear timelines or resolution. We request formal validation updates and transparent communication in line with responsible disclosure best practices. @chrispavlovski
@rumblevideo Public earnings on time, but security reports delayed for months. If Rumble can report results to shareholders promptly, it should also handle valid vulnerability reports with fair rewards and professional timelines. @chrispavlovski@rumblevideo
@rumblevideo Rumble reports millions in revenue and celebrates earnings, yet security researchers wait months for responses and fair payouts. A public company should match its financial growth with a serious, timely, and respectful bug bounty process. @rumblevideo@chrispavlovski
@chrispavlovski@TPUSA Rumble says it competes with Google and YouTube, yet refuses to value security researchers the way they do.
Google rewards bug hunters because it understands security is an investment.
Disliking Google is not a security strategy. Ignoring researchers only weakens the platform. 😏