#ITSicherheit #Crowdfense #HackerAngriff #Hacking #Schwarzmarkt #SpywareBranche #ZeroDayExploit #Zerodium https://sc.tarnkappe.info/5c6bdb
@thijs usually that should be written in the #ResponsibleDisclosure terms & conditions.
Exploit dealers like #Zerodium are able and willing to pay #Monero
and just send #XMR to a wallet of choosing.
Others may offer cash-on-delivery or a cheque to redeem at a bank...
Again: This should've been thought of beforehand!
Personally I'd do offer payment using XMR if I had any bounties to fulfil, but that's just me...
Maybe ask @ChickenPwny what's prefered?
@amuse @k8em0 Personally, I'm not a fan of "coordinated" vulnerability disclosure.
In fact I think that #Google's #ProjectZero approach is more than graceful enough.
Big #CCSS vendors like #Microsoft should be glad if someone chooses to look up the security.txt and contact them with details and not straight-up sell an exploit to #Zerodium and other #Govware - #Suppliers, cuz those pay better and ask fewer questions.
#PHP 、不正なコミット発生を受けてリポジトリをGitHubへ移行 | スラド セキュリティ
https://security.srad.jp/story/21/03/30/1643234/
#Zerodium (´・ω・) カワイソス