Full-time bug hunting: Pros and cons of an emerging careerHelp Net Security·Apr 7, 00:00 UTC · Apr 7, 2020Vulnerability55
How did Clop get its hands on the MOVEit zero day?The Record·Aug 30, 12:50 UTC · Aug 30, 2023Ransomware60
Is XBOW’s success the beginning of the end of humanCyberScoop·Jul 14, 12:46 UTC · Jul 14, 2025Vulnerability55
Why bug bounty firms want to be penetration testing companiesCyberScoop·Apr 12, 14:36 UTC · Apr 12, 2019Vulnerability55
Katie Moussouris on bug bounties, gender equity, and the myth of cybersecurity’s 'pipeline problem'The Record·Jan 19, 00:00 UTC · Jan 19, 2023Ransomware60
Anthropic is finding bugs faster than Microsoft can fix themArs Technica · Security·Jul 29, 15:52 UTC · Jul 29, 2026Vulnerability155
Fake Clickjacking Bug Bounty Reports: The Key FactsThe Hacker News·May 15, 00:00 UTC · May 15, 2022Vulnerability55
Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverageCisco Talos·Oct 9, 18:38 UTC · Oct 9, 2018VulnerabilityCVE-2018-8491CVE-2018-8460CVE-2018-8509+26 CVEs60
Dark net markets moving to adopt bug bounty programsCyberScoop·Feb 3, 17:32 UTC · Feb 3, 2017Data breach in the wild60
AWS BugBust Challenge: A global competition for developers to identify and fix software bugsHelp Net Security·Apr 20, 08:48 UTC · Apr 20, 2026Industry55
The nature of bug bounty programs is changing, and their ‘auntie’ is worriedThe Record·Jan 12, 14:08 UTC · Jan 12, 2024Exploit / PoC in the wild60
Finding 365 bugs in Microsoft Office 365Help Net Security·Mar 9, 20:09 UTC · Mar 9, 2023Vulnerability55
What Shopify has learned from five years of bug bounty programsCyberScoop·May 5, 12:37 UTC · May 5, 2020Exploit / PoC in the wild60
California's new labor law is going to impact bug bounty companies. By how much is unknown.CyberScoop·Sep 26, 12:00 UTC · Sep 26, 2019Exploit / PoC in the wild60
Samsung Launches Bug Bounty Program — Offering up to $200,000 in RewardsThe Hacker News·Sep 12, 06:33 UTC · Sep 12, 2017Data breach60
Google AI Supercharges Chrome Security, Fixing 1,072 BugsSecurity Affairs·Jul 31, 13:46 UTC · Jul 31, 2026Vulnerability155
Magento 1 still PCI compliant after 1 July 2020?Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability55
How to get better results from bug bounty programs without wasting moneyHelp Net Security·Oct 7, 00:00 UTC · Oct 7, 2025Vulnerability55
CISA warns of exploited Fortinet bugs as Microsoft issues its biggest Patch Tuesday in yearsThe Record·Jan 17, 01:12 UTC · Jan 17, 2025Vulnerability in the wildCVE-2024-55591CVE-2025-21333CVE-2025-2133460
The Intigriti Ethical Hacker Survey 2022Help Net Security·Mar 9, 20:20 UTC · Mar 9, 2023Vulnerability55
Apple AirTag Bug Enables ‘Good Samaritan’ AttackKrebs on Security·Sep 28, 16:11 UTC · Sep 28, 2021Exploit / PoC60
HackerOne concludes its bug bounty challenge with the National University of SingaporeHelp Net Security·Sep 9, 00:00 UTC · Sep 9, 2019Vulnerability55
The bug bounty market has some flaws of its ownCyberScoop·Apr 4, 15:04 UTC · Apr 4, 2018Exploit / PoC in the wild60
PoC exploit accidentally leaks for dangerous Windows PrintNightmare bugThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Exploit / PoCCVE-2021-1675CVE-2020-133760
Google touts ‘fuzzing’ open source tool after discovering TinyGLTF bugThe Record·Jan 11, 00:00 UTC · Jan 11, 2023VulnerabilityCVE-2022-300860
CISA warns of GPS bug that may roll back dates by 1,024 weeks, to March 2002The Record·Dec 18, 00:00 UTC · Dec 18, 2022Advisory55
Hackers find 122 vulnerabilities — 27 deemed critical — during first round of DHS bug bounty programCyberScoop·Apr 22, 18:26 UTC · Apr 22, 2022Vulnerability in the wild60
What is wrong with developer security training?Help Net Security·Nov 2, 00:00 UTC · Nov 2, 2021Vulnerability55
Tor Project's Bug Smash Fund raises $86K in AugustSecurity Affairs·Sep 16, 05:29 UTC · Sep 16, 2019Vulnerability55
Three's a crowd: Popular bug bounty companies are growing at an insane rateCyberScoop·Jul 28, 06:11 UTC · Jul 28, 2017Vulnerability55
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidThe Hacker News·Jul 3, 19:41 UTC · Jul 3, 2026Exploit / PoC in the wildCVE-2026-46242CVE-2026-43074CVE-2026-31431+2 CVEs160
OpenAI Expands Bug Bounty to Cover AI Abuse and 'Safety' ConcernsInfosecurity Magazine·Mar 26, 12:20 UTC · Mar 26, 2026Vulnerability55
It’s a hot 0-day summer for Apple, Google, and Microsoft security fixesArs Technica · Security·Aug 1, 17:55 UTC · Aug 1, 2023Exploit / PoCCVE-2023-37450CVE-2023-36884CVE-2023-32046+18 CVEs60
CISA adds Microsoft, Apple bugs to exploited vulnerabilities catalogThe Record·Apr 11, 21:27 UTC · Apr 11, 2023Vulnerability in the wildCVE-2023-28205CVE-2023-28206CVE-2023-28252+1 CVEs160
A Conversation With Alisa Esage, a Russian Hacker Who Had Her Company Sanctioned After the 2016 ElectionThe Record·Nov 17, 00:00 UTC · Nov 17, 2022Policy & legal155
US Govt kicked off 'Hack the Army 3.0' bug bounty programSecurity Affairs·Jan 7, 13:05 UTC · Jan 7, 2021Vulnerability55
Facebook bug gave developers access to private photos of 6.8 million usersCyberScoop·Dec 14, 17:08 UTC · Dec 14, 2018Exploit / PoC in the wild60
Grinch Bug Could be worse than Shellshock, Says ExpertsSecurity Affairs·Nov 5, 23:20 UTC · Nov 5, 2018Exploit / PoC in the wild60
Hack'em If You Can — U.S. Air Force launches Bug Bounty ProgramThe Hacker News·Apr 27, 13:49 UTC · Apr 27, 2017Data breach60
Serious Bug Exposes Sensitive Data From Millions Sites Sitting Behind CloudFlareThe Hacker News·Feb 25, 07:44 UTC · Feb 25, 2017Data breach in the wild60