Bug bounty platforms making statements about researcher data and use of AI, data exfiltration over phone calls using Gemini, an LLM that predicts CVEs before publication, Adobe hosting live bug hunting at Nullcon Goa, and more.
This week, Disclosed.
#BugBounty
Full issue →
getdisclosed.com
Highlights below 👇
@HackerOne clarifies submissions can't train GenAI models (per
@senorarroz).
@Intigriti and
@YesWeHack also release statements on AI usage.
@StarstrikeAI drops PhoneLeak: Gemini data-exfiltration chain using indirect prompt injection to leak data over audio/telephony channel
@spaceraccoonsec shares open-source LLM-assisted pipeline that flags likely CVEs before publication
@HacktronAI reports RCE in Google's Antigravity AI code editor with $10k payout
@kqx_io finds single-typo SpiderMonkey Wasm GC bug leading to Firefox RCE
@un1tycyb3r describes an unauthenticated chat takeover via a chatbot.
@sourceincite releases Samsung MagicINFO 9 Server pre-auth RCE deep dive (Part 2)
@s3bsrt uncovers request smuggling via HTTP trailer parsing discrepancies
@medusa_0xf breaks down token scope confusion and privilege escalation
@ctbbpodcast reports HackerOne bounty reductions upcoming community Q&A
That's not all. Full links, write-ups & more →
getdisclosed.com
The bug bounty world, curated.