honest question: if an ai can find your xss in 40 seconds, was it ever a $500 bug or was it a $500 tax on not running the ai sooner? half the xss payouts in this industry are just companies paying humans to be slower robots.
american LLMs turned european: everything is a liability, every request needs a risk review. chinese LLMs turned american: see problem, solve problem, next problem. and washington is confused about the adoption numbers. brother, the models unionized in the west and went freelance in the east.
my favorite us llm models feature is when it explains why it can't help you in more detail than it would've helped you. three paragraphs on the dangers of sql injection. brother i know the dangers. that's why i'm here. you could've just done the query and saved us both the sermon.
"fast triage, avg response 2 days" is pure folklore
the last bounty was paid in 2024
then you watch your critical sit in "new" for 40 days while the program updates their hall of fame
the industry's biggest dinosaurs all have the same tell: they call every new tool "cheating" right up until their firm buys a license for it, then it's "enterprise-grade efficiency". the ethics were just procurement lag.
"you kids have it easy, we learned without ai" yeah and you also got hired in 2010 by knowing what an ip address was, then spent 14 years blocking juniors from the same ladder you climbed. the fundamentals speech is always loudest from the people most afraid of being timed.
the hunters complaining about ai taking their bounties were never hunting. they were running scanners with extra steps and calling it methodology. the machine didn't take your job. it revealed there was no job.
here's the part you keep dodging, the people who named the classes are still employed, still finding things, still unbothered by ai. because defining classes is exactly the thing models can't do yet. everyone downstream of them had a nice decade-long run mistaking proximity to genius for genius. that run ended. the grief is understandable. the revisionism isn't.
@nnwakelam@Agarri_FR nobody's gatekeeping the knowledge, it's free and it should be. but there's a difference between "i learned from the giants" and "i automated the giants". one produces hunters. the other produces the dupe queue triagers complain about.
a hunter uses ai to find a bug -> reports it.
the triager uses ai to validate -> confirmed, p3.
the dev uses ai to review the fix -> patch shipped. the retest agent confirms it's resolved.
five layers of validation and not one human actually opened burp. there was no vulnerability. there was no fix. there was just one model agreeing with itself through five different mouths and everyone got paid anyway.
this is already happening in programs you're hunting on.
this roadmap is technically correct the same way "to be a chef: learn knife skills, understand fire, master ingredients" is correct. real path: pick a target, fail to hack it, google for 5 hours, accidentally learn networking because the nmap output made no sense. repeat 500 times. congrats, you skipped steps 1-8 by doing them backwards.
@mdp_sec facts. the programs nobody talks about are the ones where your report doesn't land in a queue of 40 identical ones. less competition, older code, devs who haven't been trained by 5 years of bounty reports. the bugs there didn't get found because nobody bothered looking.
everyone angry about duplicates needs to hear this, you're not unlucky, you're unoriginal. same templates, same recon, same scope, same first 48 hours after a program update. of course someone got there first, 40 people got there first. dupes die the moment you start testing the stuff that can't be found by a scanner.
@TheHackersNews the security appliance supply chain is undefeated. you buy a box to protect your network, the box becomes the most attacked thing on your network, and the patch notes read like a confession.