#security-research
6 stories taggedsecurity-research.

A 1990 Law Could Send Ethical Hackers to Prison. Dozens of Countries Are Fixing That.
Researcher Katharina Sommer mapped which nations protect good-faith security work and built a five-point blueprint to push the UK's creaking Computer Misuse Act into the present day.

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year
More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

Five Government Agencies Tell Software Makers: Open a Front Door for Bug Reporters
CISA and four allied agencies have published a joint guide urging tech companies to set up formal programmes so security researchers can safely report flaws before criminals find them first.

CISA and NSA Publish Playbook for Working With Outside Bug Hunters
New joint guidance urges software makers and online services to set up formal channels for security researchers, with clear rules, CVE assignments, and the option to lean on national response teams.

The Security Researcher Who Took On the US Legal System and Won an MBE Doing It
Jen Ellis started out running PR for a cybersecurity firm. She ended up testifying before Congress, brokering a peace deal between hackers and the Justice Department, and picking up a royal honour along the way.

Someone Finally Tested 100 AI Agents for Security. Here's the Framework They Used.
A new evaluation methodology ranks AI agents by vulnerability, blast radius, and defensive posture. The results are a useful corrective to vendor claims.