#bug bounty
13 stories taggedbug bounty.

Chrome 152 Patches 327 Security Flaws, Most Found by Google's Own AI
Google's latest browser update is its biggest in recent memory, fixing hundreds of vulnerabilities at once, with artificial intelligence doing the heavy lifting on discovery.

A human and an AI teamed up to find hundreds of hackable websites. The results rewrote the rulebook.
A PortSwigger researcher built an AI system called HTTP Terminator, guided it step by step, and together they uncovered a brand-new class of web vulnerability affecting banks and government systems.

AI-Generated Junk Is Clogging Apple's Bug Bounty, Ports Got Hit, and Wall Street Had a Bad Week Online
Three quieter stories from the past week: why Apple's security researchers are drowning in AI noise, how North Carolina ports came under digital attack, and a phishing email that opened a door into Wall Street.

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year
More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

Two Cloud Giants, Two Flaws, Zero Bug Bounties: The 'Confused Deputy' Problem That Won't Go Away
A security researcher found ways to silently hijack administrator control over both Microsoft Azure and Google Cloud infrastructure. Neither company paid a reward. One quietly fixed its flaw without saying so.

GitHub Slashes Public Bug Bounty Payouts, Reserves Top Rewards for VIPs
Starting July 27, 2026, GitHub will reduce public bug bounty payments, with top prizes reserved for an exclusive group.

Meta Paid a Researcher $78,000 to Find a Flaw That Exposed Support Chats and Personal Data
An independent security researcher discovered a hole in Meta's internal support system that could have let anyone read private conversations between users and Meta support staff. Meta patched it quietly. Then came the cheque.

Ivanti Used AI to Find a Perfect-Score Security Flaw in Its Own Software. Here Is What That Means.
The company quietly ran an AI project starting in March and says the results are already surprising even its own security chief.

AI Finds Bugs Fast. Proving They're Real Still Takes a Human.
AI tools can scan code and spit out vulnerabilities at speed, but a finding is worthless until someone shows it actually works. Here's why that gap matters for anyone worried about software security.

ServiceNow's Unauthenticated API Endpoint Left Tenant Data Exposed for Months
An API resource shipped with authentication disabled by default. Now enterprises are asking whether the 'security researcher' explanation fully covers what got accessed.

Anthropic's Mythos Shows AI Can Find Bugs Faster Than Humans. The Bug Bounty Model May Not Survive It.
Machine-speed vulnerability discovery is no longer theoretical. The question now is whether the bounty ecosystem — and the offensive security teams inside it — are priced and structured for a world where finding flaws is the easy part.

Microsoft Threatened a Bug Hunter With Legal Action. Now It's Walking That Back.
A researcher dropped unpatched zero-days with working exploits. Microsoft's first response was to reach for the lawyers. That went poorly.

Microsoft and Researcher Nightmare Eclipse Trade Public Accusations Over Disclosure Gone Wrong
A researcher who published unpatched vulnerability details says Microsoft deleted his accounts and ruined his life. Microsoft says his drops put proof-of-concept code in criminals' hands. Neither is entirely wrong.