HackerOne Bug Bounty Disclosure: webauthn-app-was-updated-based-on-public-key-se-en - RedPacket Security

Company Name: Nextcloud

RedPacket Security
HackerOne Bug Bounty Disclosure: mqtt-protocol-packet-injection-via-unchecked-connack-remaining-length-pajarori - RedPacket Security

Company Name: curl

RedPacket Security
HackerOne Bug Bounty Disclosure: information-disclosure-via-logback-configuration-injection-in-gocd-agent-aigirl - RedPacket Security

Company Name: GoCD

RedPacket Security

HackerOne Bug Bounty Disclosure: user-enumeration-via-timing-attack-in-django-mod-wsgi-authentication-backend-leads-to-account-discovery-stackered - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-user-enumeration-via-timing-attack-in-django-mod-wsgi-authentication-backend-leads-to-account-discovery-stackered/

#HackerOne #CVE #Vulnerability #OSINT #ThreatIntel #Cyber

HackerOne Bug Bounty Disclosure: user-enumeration-via-timing-attack-in-django-mod-wsgi-authentication-backend-leads-to-account-discovery-stackered - RedPacket Security

Company Name: Django

RedPacket Security
HackerOne Bug Bounty Disclosure: previous-commentor-on-post-can-still-comment-even-after-comment-permission-is-changed-to-disabled-allenjo - RedPacket Security

Company Name: LinkedIn

RedPacket Security
HackerOne Bug Bounty Disclosure: improper-access-control-access-to-active-hiring-premium-feature-filter-results-minex - RedPacket Security

Company Name: LinkedIn

RedPacket Security

@FlohEinstein @CryptoLek @turkusec As I didn't see you posting one, (missed in timeline) I thought it would be as reply here. it wasn't. So here you go - another one.

#hackerone #hackeroni

My Swiss brain is so tuned to associate stuff that ends in "...one" with certain chocolate products that I just mispronounced Hackerone (thereby confusing my colleagues).
#hackerone #toblerone #justswissthings #chocolate #Switzerland #infosec #photoshopped #notaigenerated
Wegen KI-Spam: curl stellt Bug-Bounty ein

Das curl-Projekt muss nach Jahren und Tausenden Dollar an Sicherheitsforscher sein Bug-Bounty-Programm einstellen. Der Grund: LLMs.

TARNKAPPE.INFO

@bagder personally, I find that platforms like @Hacker0x01 don't move things much further.

  • Neither are companies on there more receptible nor do things get fixed quicker as far as I can see, tho my sample size is not scientific.

Either a company / organization / project has a "#SecurityCulture" or not.

  • For most corpos #HackerOne is just a checkbox to tick when it comes to "vulnerability managment"