Yeah.. If a bug bounty program closes a report as N/A or informative (or doesn't reply in x months), the researcher should get back rights to disclose it.
Better aligns incentives towards keeping people safe and informed.
Tried out this whole "remove your unit tests" thing and found at best 6% of our units at @buildkite that weren't actually useful tests.
I genuinely think the whole discourse is flawed. Less tests, but better tests, especially for large codebases. Fast tests > slow tests, which means small tests with few dependencies. When tests fail they should immediately tell you what invariant broke. Not complicated, same as we've been doing in great scale engineering teams for the past decade.
Prompt that I ran with @AmpCode is here: https://t.co/azTD0E5vBB.
If you are submitting to bug bounty programs and not already a top researcher, you should have a careful read over this easy-reading skill, and adopt large parts of it.
The skill is used by @BugBunny_ai - the company at the top of H1's business leaderboard all year, signal 7.
Bug bounty queues are drowning in AI-generated reports. Platforms, programs, triagers and researchers all pay for it.
So we're open-sourcing the triage skill we use internally @BugBunny_ai to filter out false positives and non-actionable reports. It does two things:
1. Validates the report with an end-to-end test
2. Escalates valid bugs to their highest defensible impact, e.g. a DOM XSS pushed to full account takeover
Every report gets a verdict:
🟢 Green: validated end to end, ready to submit
🟡 Yellow: more work needed first
🔴 Red: do not submit
https://t.co/bPprHrJDUU
I don't recommend anyone start bug bounty if he didn't already
Not because of the competition
But because companies are lowering their bug bounty tables and they take months to fix/pay for bugs
@InsiderPhD@mdp_sec@fransrosen have followed Frans on twitter for over a decade I think, and only ever saw his twitter avatar. So weird seeing him unmasked in a youtube vid.
@InsiderPhD@mdp_sec Latest Critical Thinking podcast episode has an interview with @fransrosen - they discuss this near the start. https://t.co/cpSWVMYsqL
Have climbed to 2nd spot on @kong's H1 recognition page. https://t.co/pNxuRB6Qk3
Bounties are a little on the low side there, but I really do appreciate their security team's no-bullshit perspective and communication. Good team. cc: @sonicaghi
@satoki00 Congrats, that's huge!
I'm going to be in Tokyo for most of October. Aside from offensivecon, do you know of any cybersec events there this month?
@moyix Holy good-timing batman. I'm flying there next week and was hoping I could catch some cybersecurity events while there.
Do you know of anything else on in Oct? Will ask the bots soon.
Wonder how close Google’s new Argon model is to finding a bunch of these itself.. it’s probably fixing small components as it finds them rather than trying to build full chains right?
We just received a $250,000 Chrome Full Chain bonus! 🎉
We've claimed the second Full Chain bonus of 2026. Only two remain!
Under the rules, every vulnerability had to be a non-duplicate 0-day, and the entire exploit chain had to be completed before any of them were patched.
Huge thanks to @nebusecurity for discovering a V8 vulnerability in just a single day! Also, a big thank you to @_deayzl for collaborating with me on the V8 Heap Sandbox research.
P.S. KVM escapes have been getting a lot of attention. I actually captured the Full VM Escape flag in KVMCTF about three months ago. Hopefully, I'll be able to share that research soon, too!
To secure open-source software, we’re launching OSS Scanner.
We’ll use our frontier models to periodically scan opted-in open-source projects for vulnerabilities, at no cost. Our reports will provide a proof-of-concept, explanation, and suggested fix.
https://t.co/UFFrLUd25U