< ciso
brief />
Tag Banner

All news with #bug bounty tag

45 articles

Samsung Galaxy S26 Hacked Multiple Times at Pwn2Own

🔒 On day two of Pwn2Own Ireland 2026, researchers earned $232,500 after exploiting 45 distinct zero-day vulnerabilities. The Samsung Galaxy S26 was compromised three times by teams including KAIST Hacking Lab, PetoWorks, and Mobile Hacking Lab. Other notable wins included a rapid Sonos Era 300 exploit and a $40,000 award for breaching Dynamo in the AI Infrastructure category. ZDI enforces vendor 90-day patch windows after disclosure.
read more →

Google pause spotlights AI-driven triage challenge

🔍 Google paused certain bug bounty submissions after a surge of largely automated, low-quality reports stretched its validation capacity. The company had already tightened rules and raised evidence requirements to reduce false positives, but high volumes of AI-generated findings continue to challenge triage workflows. Experts warn that unchecked report floods can waste engineering time and that organizations should treat triage as a security capability, requiring reproducible evidence and reachability checks. AI can discover real vulnerabilities but also produces plausible, costly false leads that must be filtered before remediation.
read more →

Google pauses OSS product bug bounty rewards

🛡️ Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) effective October 1, citing a significant rise in automated, largely invalid reports. Reports filed before October 1 and supply chain compromise reports remain accepted, and the company says the pause is temporary while it reworks the program with an update promised in Q1 2027. The pause removed listed product vulnerability payouts for flagship and important projects, though supply chain and other issue rewards remain in place.
read more →

Google pauses OSS bug bounty until 2027

🛑 Google has paused its Open Source Vulnerability Rewards Program (OSS VRP) until 2027 after a surge of automated, largely invalid submissions. Launched in August 2022, the OSS VRP rewards researchers for finding flaws in Google-hosted open-source projects and related repository configurations. The pause excludes supply-chain reports and already filed submissions, while Google says it will reformat the program and provide an update in Q1 2027. Researchers are urged to use other Google VRPs or the Patch Rewards Program in the interim.
read more →

Google pauses OSS bug bounty amid AI report surge

🔒 Google has temporarily suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after a flood of largely invalid AI-generated reports. The pause doesn't affect supply chain reports or previously submitted product vulnerabilities, and researchers can still use the Patch Rewards Program or Cloud VRP. Google plans to rework the OSS VRP to address automated submission issues and will provide an update in Q1 2027.
read more →

AWS expands Continuum penetration testing to six regions

🔒 AWS Continuum for Penetration Testing (AWS Security Agent) is now available in six additional Regions, enabling localized penetration testing for web applications and APIs. The expansion covers Asia Pacific (Seoul), Canada (Montreal), Europe (London), US East (Columbus), Europe (Paris), and Europe (Stockholm). Organizations can run testing closer to production to meet data residency and compliance needs while preserving existing Region support.
read more →

AI-aided chain let researchers hijack OpenAI staff accounts

🔎 Three Hacktron researchers used Anthropic's Claude Opus 5 to chain a Discourse libheif image bug with an OpenAI login weakness and take over ChatGPT and Codex accounts of several OpenAI employees. The team reported the issue, created a benign pull request to prove access, and stopped; OpenAI patched and awarded a $6,500 bounty. The exploit relied on an outdated libheif in the forum VM and the shared SSO between the forum and internal tools, highlighting risks for services that accept HEIF/AVIF images and reuse sign-on across trust boundaries.
read more →

Apple limits bug reports amid AI-generated spam

🛡️ Apple has imposed tight submission limits and a 30-day cool-off on its bug bounty portal after being overwhelmed by low-quality, AI-generated vulnerability reports that often describe non-existent flaws. These AI submissions can include syntactically valid code and plausible technical explanations, consuming engineer time to triage. The restriction was triggered after a surge of reports from an Italian startup using a GPT-5.5 scanner, which inadvertently locked out a researcher who’d found a critical macOS zero-day. Apple and other platforms like GitHub are evolving processes to filter AI slop while balancing the risk that genuine, valuable reports may be discouraged or diverted to exploit brokers.
read more →

GitHub halves public bug bounty payouts starting July 27

🔔 GitHub will cut public bug bounty payments by roughly half at every severity level beginning July 27, 2026, moving from flexible ranges to fixed payouts. Critical rewards drop to $10,000 while the invite-only VIP tier will pay $30,000 or more. Reports submitted before the cutoff keep prior terms. GitHub says the change aims to reduce noise and speed responses for established researchers while retaining discretionary bonuses for exceptional work.
read more →

GitHub reduces low-impact bounties as AI submissions surge

🔒 GitHub is shifting low-impact bug bounty payouts from cash to swag and asking researchers to stop submitting low-quality or out-of-scope reports. The company says a sharp rise in submissions—exacerbated by generative AI tools—has produced many reports that don’t show meaningful security impact. GitHub welcomes AI-assisted research but requires human validation of AI-generated findings and will exclude certain report types from rewards. The change aims to speed triage and prioritize substantive vulnerabilities.
read more →

Google Raises Bug Bounty Maximums for Android and Chrome

🔒Google has increased maximum payouts for its vulnerability reward programs, raising the top prize to $1.5 million. The new maximum applies to critical issues impacting Android, with reports indicating the full amount requires compromising the Pixel Titan M2 security chip. Rewards for vulnerabilities in Chrome now top out at $250,000. Since launching its programs in 2010, Google has paid $81.6 million to researchers.
read more →

Google boosts top Android exploit rewards to $1.5M

🔐Google updated its Android and Chrome vulnerability rewards, increasing top-tier payouts for the most difficult exploits while lowering awards for issues AI has made easier to find. The highest Android prize is $1.5 million for zero-click, full-chain persistent exploits against a Pixel Titan M2 security chip, with $750,000 for non-persistent variants. For Chrome, full-chain browser process exploits pay up to $250,000 plus a $250,128 bonus for exploiting MiraclePtr-protected allocations; Google also narrows Android scope to Linux kernel bugs in Google-maintained components unless concrete device exploitability is shown.
read more →

Microsoft Pays $2.3M for Cloud and AI Flaws at Zero Day Quest

🛡️ Microsoft awarded $2.3 million to security researchers after receiving nearly 700 submissions during this year’s Zero Day Quest hacking contest, compensating teams for high‑impact cloud and AI vulnerabilities uncovered at the live event. Participants from more than 20 countries tested within authorized environments under Microsoft’s Rules of Engagement and demonstrated issues such as credential exposure, SSRF chains, and cross‑tenant access without accessing customer data. The contest is part of the Secure Future Initiative, and Microsoft said findings will be shared through the CVE program to strengthen cloud and AI security.
read more →

Internet Bug Bounty Pauses Payouts Amid AI Advances

🛑 The Internet Bug Bounty program, administered by HackerOne and backed by multiple major software companies, has paused submissions and payouts while it reassesses how best to support open source security. HackerOne said the rise of AI-assisted vulnerability discovery has increased both coverage and speed, shifting the balance between new findings and remediation capacity. Projects such as Node.js will continue to accept and triage reports via HackerOne but may not issue rewards from the paused fund. Similar changes have hit other programs, including curl and recent restrictions at Google's open source rewards effort.
read more →

Google VRP 2025 Year in Review: Growth and Milestones

🛡️ In 2025 Google’s Vulnerability Reward Program (VRP) celebrated its 15th anniversary and awarded over $17 million to more than 700 researchers worldwide — a 40%+ increase versus 2024. The year introduced a standalone AI VRP, extended Chrome rewards for AI features, and launched a patch rewards program for OSV-SCALIBR. Multiple bugSWAT events and the ESCAL8 conference generated hundreds of reports and significant payouts. Google reaffirms its commitment to collaboration, transparency, and continued events in 2026.
read more →

OpenAI unveils Safety Bug Bounty to limit AI abuse

🛡️ OpenAI has launched a new Safety Bug Bounty, hosted on Bugcrowd, to solicit researcher reports of AI abuse and safety risks across its products. Announced March 26, it complements the existing Security Bug Bounty and targets issues like agentic risks (MCP abuse, prompt injection, data exfiltration), account integrity violations, and proprietary-information exposures. OpenAI clarified scope limits, excludes low-impact jailbreaks, runs private campaigns for certain harms, and will triage submissions between safety and security programs.
read more →

Google paid $17.1M to security researchers in 2025

💰 Google paid $17.1 million to 747 security researchers in 2025 through its Vulnerability Reward Program, an all-time annual high and more than a 40% increase over 2024. The company said it has awarded over $81.6 million in bounties since 2010, with the top single reward reaching $250,000. In 2025 Google launched an AI Vulnerability Rewards Program, added AI-focused categories to the Chrome VRP, and introduced a rewards track for OSV-SCALIBR. Program-specific payouts included Android & Google Devices (~$2.9M), Chrome (~$3.72M), and Cloud (~$3.57M).
read more →

curl ends HackerOne bug bounty after surge of AI reports

🔒 The curl project will end its HackerOne bug bounty program after being overwhelmed by a surge of low-quality, apparently AI-generated vulnerability reports that strained the small security team and harmed maintainers' wellbeing. Founder Daniel Stenberg said the torrent of AI slop submissions created a high triage burden. The project will accept HackerOne reports through January 31, 2026, then move to direct reporting via GitHub with no monetary rewards.
read more →

Researchers Exploit 29 Zero-Days at Pwn2Own Automotive

🚗 On the second day of Pwn2Own Automotive 2026, security researchers earned $439,250 after exploiting 29 unique zero-day vulnerabilities in EV chargers, in-vehicle infotainment systems, and automotive operating systems. Contestants targeted fully patched devices such as the Phoenix Contact CHARX SEC-3150, ChargePoint Home Flex, and the Grizzl-E Smart 40A charging station. Fuzzware.io led the leaderboard after two days, and organizers confirmed vendors have 90 days to issue fixes before public disclosure by the Zero Day Initiative.
read more →

Curl ends paid bug bounty program over AI-generated reports

🛑 Curl has ended paid rewards in its bug bounty program after a surge of low-quality, AI-generated vulnerability reports overwhelmed the project's triage resources. Chief administrator Daniel Stenberg said the volume of "AI slop" and generally poor reports left maintainers unable to keep up. Over the years Curl paid $101,020 in bounties, and the project joins other vendors reassessing programs as automated tooling reshapes vulnerability disclosure.
read more →