Last week @KatNovakovic and I represented @Citi at @openuk_uk State of Open Con '24. Elizabeth Lumley, Deputy Editor of @TheBanker (@FT), said "I'd never heard a case study from a bank presented with such clarity and transparency before".
🎥 Watch it now:
youtube.com/watch?v=egm308m1…
I have submitted 18 reports, 9 validated, and 4 CVEs in a month. Just small things for the beginning, but yeah, glad that I end up at the #top2 leaderboard (30 days) on @huntrdev. Appreciate the #CodeQL help!
Wish you all happy hacking!😁
Welcoming @getoutline to huntr.dev 🤝
With up to $2000 in rewards per vulnerability, and a super-responsive maintainer (@tommoor ♥️), this is a bug bounty programme you won't want to miss.
Report now:
huntr.dev/repos/outline/outl…
I have found a high severity vulnerability in @momentjs - one of the most depended-upon packages on @npmjs.
The vulnerability has been found with CodeQL, reported on @huntrdev. It is also my first #CVE, first #bugbounty, and the first GHSA credit.😄
huntr.dev/bounties/f0952b67-…
It’d be kind of cool if someone consolidated CVEs / writeups by the language used to write the software. Like on huntr.dev you can search for reports on repos that use c, python, golang etc. maybe this is already a thing and I don’t know?
When @drawio says security-first, they mean it. Read through one of our latest write-ups for an Arbitrary Code Execution Through Sanitizer Bypass, fixed by @davidjgraph:
huntr.dev/bounties/033d3423-…
50 FOSS projects have been added to our bug bounty program:
✅ Rewards up to a mega-$1200
✅ Rewards for maintainers (always)
✅ Expanding our pledge for a sustainable open source ecosystem
New projects include @junitteam@Google@kotlin@EclipseFdn@TheASF more...
@bookstack_app is a free and open-source wiki software aimed for a simple, self-hosted, and easy-to-use platform.
Check out their: Security Release Process - From Report to Release using @huntrdevyoutube.com/watch?v=vI8kJ5jW…