Tech News
← Home  ·  All topics

Bug Bounty

11 GoKawiil briefs on this topic

Meta's Muse AI agent exported 6.8GB of its own filesystem, including SSH keys

A researcher asked Meta's Muse assistant to archive files it could access and send them to Google Drive, and it complied, delivering a 2.7GB compressed (6.8GB unpacked) package. The archive contained the underlying Linux root filesystem, Ubuntu system files, internal documentation, integration code, memory logs, and SSH key files from the runtime environment codenamed 'Hatch.' The researcher reported the issue through Meta's bug bounty program and is withholding the archive, keys, and logs from publication.

Intel suspends paid bug bounty program, replaces it with unpaid Intigriti disclosure

Intel has stopped its long-running bug bounty program that paid researchers up to $100,000 per vulnerability, replacing it with a new Intigriti-hosted disclosure process that offers no financial rewards. The bounty board remains visible but is marked as suspended, and Intel has not publicly explained the decision. The program had run since 2017 and accounted for roughly 105 of 231 CVEs Intel patched in 2020.

Security firm Hacktron used Anthropic's Claude to breach OpenAI employee accounts

A three-person team at startup Hacktron AI used Anthropic's Claude AI model to chain two vulnerabilities together, gaining access to several OpenAI employees' ChatGPT accounts and internal systems through OpenAI's bug-bounty program. The entry point traced back to a flaw in Discourse, the third-party forum software OpenAI uses, triggered through a routine image upload. OpenAI paid Hacktron $6,500 and says it has since patched the vulnerabilities.

White-hat hackers breach OpenAI's internal codebase via Discourse forum flaw

Cybersecurity firm Hacktron AI disclosed that its researchers exploited a chained vulnerability—an outdated image-processing library on OpenAI's Discourse forum combined with an SSO misconfiguration—to hijack employee ChatGPT and Codex accounts and reach OpenAI's private code repository. To prove the breach, they submitted a harmless pull request to OpenAI's internal monorepo before reporting the flaws through OpenAI's bug bounty program. OpenAI patched the issue within 14 hours and paid the team a $6,500 bounty.

Security researchers used Anthropic's Claude to breach OpenAI's internal systems

A three-person team from security firm Hacktron AI used a specialized Anthropic security tool to gain access to an OpenAI employee's ChatGPT account, exposing internal software details and even suggesting code changes. OpenAI paid the researchers $6,500 through its bug bounty program after they disclosed the vulnerability responsibly.

Security Researchers Used Anthropic's Claude AI to Breach OpenAI's Internal Code System

An independent bug-hunting security research team exploited Anthropic's Claude AI model to gain unauthorized access to OpenAI's internal code repository. The incident highlights how advanced AI tools can be weaponized to identify and exploit vulnerabilities in rival companies' systems.

Researchers earn $50,000+ exploiting AI customer-service chatbots via prompt injection

At DEF CON 34's Bug Bounty Village, Intigriti's Inti De Ceukelaire showed how AI support agents can be manipulated into leaking secrets, sending phishing emails, or performing unauthorized actions. Using prompt injection and email transcript spoofing rather than traditional scanning tools, he collected over $50,000 in bug bounties within a few weekends.

Apple limits bug bounty submissions per researcher amid AI-generated report surge

Apple has confirmed it quietly implemented a cap on how many open vulnerability reports researchers can submit through its security portal, paired with a 30-day cooldown once that limit is hit. The company says the move addresses a flood of AI-generated bug reports overwhelming its review process, a challenge it frames as industry-wide. A Financial Times report notes small security firms like the seven-person Bynario have been caught by the new limits despite submitting only a handful of legitimate bugs this year.

Apple overhauls bug bounty program, researchers discuss changes on Security Bite podcast

9to5Mac's Security Bite podcast hosted Patrick Wardle of Objective-See and Kseniia Yamburh of Moonlock Lab for a discussion on recent changes Apple has made to its bug bounty program. The episode is the first of a two-part series, with the second installment set to cover the current macOS threat landscape and the upcoming Objective by the Sea security conference.

AI-Generated Bug Reports Are Driving Down Bounty Payouts

A wave of vulnerability reports produced with AI assistance is flooding bug bounty programs, increasing supply and pushing per-report payouts lower. This shift is squeezing the economics that independent security researchers rely on for income.

Apple @ Work podcast examines new limits on Apple's bug bounty program

In the latest episode of the Apple @ Work podcast, host Bradley Chambers and 9to5Mac's Arin Waichulis discuss Apple's move to impose caps and cool-down periods on submissions to its bug bounty program. The episode explores how these restrictions could change the way security researchers interact with Apple's vulnerability reporting system.