Joined March 2018
70 Photos and videos
"brutecat is super talented", "luckily I'm not oncall ;)", "incredible" These are all real quotes from Googlers after seeing this blog post. Amazing work @brutecat, thank you for sharing!
Jun 11
Hacking Google with A.I. for $500,000 brutecat.com/r/hacking-googl…
2
24
543
31,785
πŸ“’ PSA for security researchers! In our latest post, we're taking a closer look at how Google Spark (which was recently launched) works, ways to approach bug hunting in Spark, and how to distinguish high-impact vulnerabilities from expected system behavior πŸ‘‡ bughunters.google.com/blog/s…
3
7
107
8,762
πŸ“£Blast from the pastπŸ“£ This post takes us back to a flaw discovered in 2010: while technology has advanced, the general story of how the flaw was detected is still a great example of effectively identifying and remediating a security issue. bughunters.google.com/blog/b…
2
3
32
2,942
πŸ“’ More on Google's approach to post-quantum cryptography πŸ” This time, we're taking a closer look at digital signatures and the complex challenges they present, and discussing the opinionated paths we are taking at Google in this space. bughunters.google.com/blog/n…
6
42
3,956
More on passkeys πŸ”! This time we are focusing on storage options, in particular the differences between using a password manager vs. a hardware security key to store your credentials, and why you might choose one option over the other. bughunters.google.com/blog/h…
2
19
2,250
In April 2026, we held the latest edition of bugSWAT (our live event for security researchers) in Seoul, South Korea. For more information on this edition's focus, its impact & winners, as well as bugSWAT in general, see πŸ‘‡ bughunters.google.com/blog/b…
2
13
78
7,201
πŸ“£πŸ“’ Calling all Android and Chrome bug hunters πŸ§‘β€πŸ’»πŸ”Ž! We're updating our Android & Chrome VRP programs to ensure we can continue to reward the most challenging and impactful vulnerabilities researchers find in our products. For details, πŸ‘‡ bughunters.google.com/blog/e…
22
33
208
143,308
Our Google Cloud VRP researchers don't want to miss this! πŸ”₯ Check out Omer's (@omer_asfu) cross-tenant bucket squatting research.
I achieved a cross-tenant #RCE in #GoogleCloud simply by abusing predictable bucket names. πŸͺ£ In my latest research for @FocalSecurity, I look into "Bucket Squatting" - a cross-tenant attack that landed me 3 critical vulnerabilities in GCP. Here is how it works:
2
12
102
13,758
πŸ“’πŸ“’πŸ“’ Attention bug hunters! The Google VRP is updating its reward model, with a focus on the impact of vulnerabilities and the sensitivity of the data involved. To this end, we're introducing two dimensions: Information Tiers and Action Criticality. πŸ‘€πŸ‘‡ bughunters.google.com/blog/s…
9
38
241
20,692
Ever wondered how passkeys πŸ” work, and how they improve on classic passwords πŸ”€? For more details, see our latest post, and you'll also learn what makes passkeys particularly resistant against phishing 🐟. bughunters.google.com/blog/p…
1
4
40
11,207
πŸ“’ Open source security researchers, take note: we've updated the OSS VRP rules! We're emphasizing the need for actionable reports and verifiable reproduction steps – to allow us to focus on critical threats with real-world impact. For more details πŸ‘‡ bughunters.google.com/blog/o…
1
13
78
8,121
GCP VRP Secrets? 🀫 Hear from the program leads! Michael Cote (linkedin.com/in/michaelpatri…) & Darby Hopkins (linkedin.com/in/darbyhopkins) join @ctbbpodcast to talk shop: killer report tips, program insights & boosting your bounty game on Google Cloud. 🎧 youtu.be/7u6xpVhEpBA #GoogleVRP #BugBounty #CloudSecurity #GCP

1
6
58
9,136
Our Google Cloud VRP researchers don't miss! πŸ”₯ Check out @terminatorLM's latest Looker research uncovering 9 novel cross-tenant vulns in Looker. See how it was done: πŸ‘‡
🫣LeakyLooker: 1 Cross-tenant vulnerability? How about 9? (1/10)🧡 I’m incredibly proud to share LeakyLooker. I discovered 9 novel cross-tenant vulnerabilities in Google Cloud’s Looker Studio that broke fundamental design assumptions. Here is how I broke tenant isolation: πŸ‘‡
1
11
89
8,736
πŸ“£πŸ“£πŸ“£ Hot off the press: 2025 highlights of Google's vulnerability reward programs! Notably, we awarded an all-time high of over $17 million in rewards πŸ’° and kicked off the dedicated AI VRP πŸ€–. Thank you to our incredible bug hunting community πŸ§‘β€πŸ’»πŸ§‘β€πŸ’»πŸ§‘β€πŸ’»!!! bughunters.google.com/blog/g…
3
9
92
18,137
πŸ“’ Interested in AI and agent security at GoogleπŸ›‘οΈ? This post looks at how we mitigated the risk of URL-based data exfiltration through provenance checks and sanitization – effectively blocking a prompt injection-based exploitation vector. bughunters.google.com/blog/m…
5
18
107
19,843
Offline authentication on Android πŸ€– πŸ”’? Find out how the FIDO alliances's Hybrid transport architecture was expanded to support this crucial scenario, and how this increases reliability and unlocks many new use cases. bughunters.google.com/blog/h…
1
3
46
5,881
Next up in our series on Android and authentication πŸ€– πŸ”’: Learn how the FIDO Alliance's Hybrid protocol has been expanded beyond CTAP messages to also support generic JSON, and which new use cases this extended approach enables. bughunters.google.com/blog/h…
1
6
41
4,701
Curious how we go about security reviews at Google? In this case, we teamed up with Intel to take a closer look at Intel Trust Domain Extensions (TDX) 1.5 and help secure the confidential computing space! For the details, πŸ‘‡ bughunters.google.com/blog/a…
2
20
93
22,715
πŸ”’ Want to move beyond passwords? Check out this beginner's guide to Cross-Device Passkeys! Learn how "Hybrid transport" uses QR codes and Bluetooth to let you sign in securely on any device – even public ones – without ever sharing your private keys. bughunters.google.com/blog/p…
1
17
74
6,633