#Bugcrowd

RedPacket SecurityRedPacketSecurity
2025-12-18

BugCrowd Bug Bounty Disclosure: P4 - Publicly accessible phpinfo() exposes detailed server configuration - MattKingst - redpacketsecurity.com/bugcrowd

RedPacket SecurityRedPacketSecurity
2025-12-18

BugCrowd Bug Bounty Disclosure: P2 - IDOR that allows disclosing Username,Email,PIN,FirstName,LastName,UEI,FirmName,Address,PhoneNumbers etc of PROSAMS application users. - - redpacketsecurity.com/bugcrowd

RedPacket SecurityRedPacketSecurity
2025-12-18

BugCrowd Bug Bounty Disclosure: P4 - Unauthenticated Metrics Endpoint Exposes Sensitive Internal Grafana & NASA Infrastructure Data - whitebear_0one - redpacketsecurity.com/bugcrowd

RedPacket SecurityRedPacketSecurity
2025-12-18

BugCrowd Bug Bounty Disclosure: P4 - NASA NLSP API discloses internal usernames and system role mappings to unauthenticated users - c3L0Mu1d3R - redpacketsecurity.com/bugcrowd

RedPacket SecurityRedPacketSecurity
2025-12-17

BugCrowd Bug Bounty Disclosure: P5 - Server-Side Request Forgery (SSRF) → Local File Read (High / Critical) - Ninadgowda - redpacketsecurity.com/bugcrowd

RedPacket SecurityRedPacketSecurity
2025-12-17

BugCrowd Bug Bounty Disclosure: P5 - Reflected Cross Site Scripting (XSS) Via POST request on adapt-public.aetc.appdat.jsc.nasa.gov - Kent_Shane14 - redpacketsecurity.com/bugcrowd

RedPacket SecurityRedPacketSecurity
2025-12-17
RedPacket SecurityRedPacketSecurity
2025-12-13
RedPacket SecurityRedPacketSecurity
2025-12-12

BugCrowd Bug Bounty Disclosure: P3 - Anonymous Access to Jira Filter API Exposes Internal Usernames, Emails, and Organizational Structure - c3L0Mu1d3R - redpacketsecurity.com/bugcrowd

RedPacket SecurityRedPacketSecurity
2025-12-10

BugCrowd Bug Bounty Disclosure: P5 - 403 Bypass Leading to Exposed WordPress Authentication Endpoint on NASA Science Domain - Ninadgowda - redpacketsecurity.com/bugcrowd

RedPacket SecurityRedPacketSecurity
2025-12-05

BugCrowd Bug Bounty Disclosure: P5 - Password Reset Token Exposed in Redirect URL — GLOBE.gov (Sensitive Token in URL, P4) - Ninadgowda - redpacketsecurity.com/bugcrowd

RedPacket SecurityRedPacketSecurity
2025-11-26
2025-11-24

AI is accelerating security workflows - but humans still own the outcomes.

David Brumley of Bugcrowd explains why guardrails, human-in-the-loop oversight, and POC validation remain essential as AI agents expand.

Full interview:
technadu.com/ai-runs-fast-but-

#CyberSecurity #AI #Bugcrowd #AppSec

AI Runs Fast But Humans Steer: Discussing the Cold Truth About Ownership and Leading the Tech
RedPacket SecurityRedPacketSecurity
2025-11-22
RedPacket SecurityRedPacketSecurity
2025-11-20

BugCrowd Bug Bounty Disclosure: P5 - NSPIRES login and sensitive pages lack anti-frame protections → Clickjacking (UI redress) escalated to credential capture & forced action - madhu873 - redpacketsecurity.com/bugcrowd

RedPacket SecurityRedPacketSecurity
2025-11-20

BugCrowd Bug Bounty Disclosure: P1 - IDOR that allows disclosing Username,Email,FirstName,LastName,Address,PhoneNumbers of PROSAMS application users. - - redpacketsecurity.com/bugcrowd

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst