HackerOne takes an axe to its bug bounty rewards
Critical flaw payouts slashed by more than 75% Continue reading HackerOne takes an axe to its bug bounty rewards
Collaborate Disseminate
Critical flaw payouts slashed by more than 75% Continue reading HackerOne takes an axe to its bug bounty rewards
Leakage blamed on treacherous friends exposed unencrypted credentials, email addresses Continue reading Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach
Switchzilla says attackers could access sensitive data and make configuration changes across tenant boundaries through vulnerable internal APIs Continue reading Cisco serves up yet another perfect 10 bug with Secure Workload admin flaw
Redmond open sources two tools for building and maintaining safer agents Continue reading Microsoft storms RAMPART, adds Clarity to agentic AI safety
Failing to disable a former employee’s account was a huge mistake Continue reading Zombie user account let hackers control the city’s water
Another day, another AI bug silently fixed with no CVE and no public disclosure Continue reading Even Claude agrees: hole in its sandbox was real and dangerous
Initial assessment says customer data spared while users wonder what else may have slipped out Continue reading GitHub says internal repos exfiltrated after poisoned VS Code extension attack
A Freedom of Information Act request shows the extent of the surveillance Continue reading London’s police asked Big Tech for comms data over 700,000 times last year
‘Thousands’ of US victims, including 12+ machines owned and operated by Redmond Continue reading Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware
I wonder what’s in ‘external-secret-repo-creds.yaml’ and ‘AWS-Workspace-Firefox-Passwords.csv’? Continue reading America’s top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames