#bug-bounty

[ follow ]
fromTheregister
1 day ago

Microsoft now buys bugs, with or without a bounty program

Under the new model, MSRC will pay researchers who report critical vulnerabilities that have a demonstrable impact on Microsoft's online services. "Regardless of whether the code is owned and managed by Microsoft, a third party, or is open source, we will do whatever it takes to remediate the issue," Gallagher said. "Our goal is to incentivize research on the highest risk areas, especially the areas that threat actors are most likely to exploit."
Information security
#vulnerability-disclosure
#cloud-security
Information security
fromComputerWeekly.com
4 days ago

Why bug bounty schemes have not led to secure software | Computer Weekly

Software companies need legal liability for insecure code because bug bounties create exploitative, speculative labor and leave many security researchers underpaid and legally exposed.
fromTechzine Global
1 month ago

Vulnerability in Claude enables data leak via prompt

Anthropic's AI assistant, Claude, appears vulnerable to an attack that allows private data to be sent to an attacker without detection. Anthropic confirms that it is aware of the risk. The company states that users must be vigilant and interrupt the process as soon as they notice suspicious activity. The discovery comes from researcher Johann Rehberger, also known as Wunderwuzzi, who has previously uncovered several vulnerabilities in AI systems, writes The Register.
Information security
#iot-security
#apple
Information security
fromSecurityWeek
2 months ago

Google Offers Up to $20,000 in New AI Bug Bounty Program

Google launched a dedicated AI Vulnerability Reward Program excluding prompt injections, jailbreaks, and alignment issues while prioritizing security and abuse vulnerability reports.
fromZDNET
2 months ago

Google will pay you up to $30,000 in rewards to find bugs in its AI products

On Monday, Google security engineering managers Jason Parsons and Zak Bennett said in a blog post that the new program, an extension of the tech giant's existing Abuse Vulnerability Reward Program (VRP), will incentivize researchers and bug bounty hunters to focus on "high-impact abuse issues and security vulnerabilities" in Google products and services.
Artificial intelligence
fromDeveloper Tech News
4 months ago

Can open-source survive the onslaught of AI slop?

Daniel Stenberg stated, "does not seem to slow down. On the contrary, it seems that we have recently not only received more AI slop but also more human slop."
Tech industry
fromTechCrunch
4 months ago

Exclusive: Meta fixes bug that could leak users' AI prompts and generated content

Meta has addressed a security vulnerability that allowed users to access private prompts and AI-generated responses of others, revealing major concerns with data authorization.
Privacy professionals
Growth hacking
fromHackernoon
2 years ago

1inch Rolls Out Expanded Bug Bounties With Rewards Up To $500K | HackerNoon

1inch launches upgraded bug bounty programs with rewards up to $500,000 to enhance DeFi security across key components.
#cybersecurity
fromHackernoon
3 years ago
Information security

Digital Defenders: Meet Syed Shahzaib Shah, Pakistan's Ethical Hacker Changing the Game | HackerNoon

Shahzaib Shah exemplifies how curiosity and dedication can propel impactful careers in cybersecurity, regardless of geographic or economic constraints.
fromMedium
8 months ago
Tech industry

Earn Money by Discovering Bugs

Bug bounty hunting allows anyone to earn money by finding vulnerabilities in websites.
fromHackernoon
3 years ago
Information security

Digital Defenders: Meet Syed Shahzaib Shah, Pakistan's Ethical Hacker Changing the Game | HackerNoon

[ Load more ]