#HackerOne

2025-05-20

If you have followed the rant of @bagder (the maintainer of #curl) about #AI generated reports on #hackerone (linkedin.com/posts/danielstenb) and you agree with him, this discussion on #GitHub might be for you github.com/orgs/community/disc
The #FOSS world might get flooded even more with #Copilot generated issues and PRs. All powered by GitHub

#opensource #OSS #softwaredevelopment

RedPacket SecurityRedPacketSecurity
2025-05-15

HackerOne Bug Bounty Disclosure: -xenoblade-chronicles-x-definitive-edition-improper-validation-of-names-allows-injecting-formatting-tags-and-bypassing-profanity-filter-roccodev - redpacketsecurity.com/hackeron

RedPacket SecurityRedPacketSecurity
2025-05-15
RedPacket SecurityRedPacketSecurity
2025-05-15

HackerOne Bug Bounty Disclosure: corrupted-pointer-in-node-fs-readfileutf-const-functioncallbackinfo-value-args-when-args-is-a-string-justinnietzel - redpacketsecurity.com/hackeron

RedPacket SecurityRedPacketSecurity
2025-05-15

HackerOne Bug Bounty Disclosure: -xenoblade-chronicles-x-definitive-edition-unrestricted-rpcs-allow-dos-and-writing-arbitrary-flags-remotely-roccodev - redpacketsecurity.com/hackeron

RedPacket SecurityRedPacketSecurity
2025-05-15
Wen Bin :verified:kongwenbin@infosec.exchange
2025-05-12

❓ How can bug bounty programs …
1️⃣ Keep hackers engaged in the long term?
2️⃣ Effectively increase the amount of good quality reports that you receive?
3️⃣ Stand out from competition and be the program that hackers choose to hack on?

📽️ In this video, I covered 5 tips that can allow any bug bounty programs to stand out from the rest. If you implement them, you can expect an increased participation from skilled and good hackers (or security researchers) and a consistent stream of valuable vulnerability submissions! Most importantly, are you ready to handle the resulting high quality reports? 😊

🫵 Hackers, if these tips hit the mark, please share them with your favourite bug bounty programs! Your input could lead to improvements like loyalty programs and direct report submissions (skip platform analysts or triage teams). Let's level up the bug bounty landscape together! 😎

⬇️⬇️⬇️

youtu.be/msr-7ZtmLdE

#bugbounty #bugbountytips #togetherwehitharder #hackerone #ittakesacrowd #outhackthemall #bugcrowd #bugcrowdtipjar #hackwithintigriti #intigriti #yeswehack #yeswerhackers #ethicalhacking #whitehat

Five tips for boosting long term engagement in your bug bounty program! Check out the video for more information
Ars Technica Newsarstechnica@c.im
2025-05-07

Open source project curl is sick of users submitting “AI slop” vulnerabilities arstechni.ca/LAhpm #vulnerabilities #bugreports #hackerone #security #Tech #curl #AI

talou ⏚🍉talou@mamot.fr
2025-05-06

#hackerone #curl | Daniel Stenberg | 158 comments

archive.is/IZOug
#shaarli

Glyphglyph
2025-05-05

@LukaszOlejnik

The image is a screenshot of a post from "Daniel Stenberg, curl CEO. Code Emitting Organism" with a timestamp of "16h", showing that it was edited:

That's it. I've had it. I'm putting my foot down on this craziness.

1. Every reporter submitting security reports on for now needs to answer this question:
"Did you use an Al to find the problem or generate this submission?"

(continued in next post)

daniel:// stenberg://bagder
2025-05-05

I mentioned the AI slop thing on

291,512 Impressions
up 3,240.4% vs. prior 7 days
2025-05-05

Why does the #AISlop problem exist at #hackerone (and likely other bug bounty platforms)?

Because apparently it works: hackerone.com/evilginx/hacktiv

It seems that some projects pay bounties for such AI Slop reports.

original: https://mamot.fr/@sknob/114398779969680176
RedPacket SecurityRedPacketSecurity
2025-05-03
RedPacket SecurityRedPacketSecurity
2025-04-12
RedPacket SecurityRedPacketSecurity
2025-04-09
RedPacket SecurityRedPacketSecurity
2025-04-07

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst