What a fall from grace for HackerOne, once my favourite bug-bounty platform. 😬
"HackerOne triage analyst incorrectly closes the report as a duplicate [...]"

April 27th - What happened with our feature flag configuration | The ClickUp Blog
On April 27, 2026, a security researcher publicly disclosed that ClickUp’s client-side feature flag configuration exposed personally identifiable information. Specifically, 893 customer email addresses were embedded in feature flag targeting rules, along with one flag that improperly referenced a customer’s API token, used during an incident response to rate-limit traffic from that workspace. We should […]



