This week, Disclosed.
#BugBounty
H1-65 Singapore & H1-468 Stockholm winners, new H1-Elites, Google’s AI VRP, YesWeHack wins EU tender, new programs, tools, write-ups & videos — and more.
Full issue →
getDisclosed.com
Highlights below 👇
@tiktok_us &
@okx H1-65 (Singapore) winners: MVH —
@corraldev; Community Choice —
@Agornello; Best Collab —
@kevin_mizu,
@infosec_au,
@hash_kitten &
@HackerOn2Wheels,
@ledz1996.
@Hacker0x01 H1-468 (Stockholm) winners:
@Blaklis_,
@snorlhax,
@DoomerOutrun (MVH & Best Collab);
@holyfield (Eliminator);
@Rhynorater (Eradicator/Exterminator);
@joaxcar (Community Choice);
@alicanact60 (Epic Unreal Hacker).
New
@Hacker0x01 H1-Elites for 2025:
@niemand_sec,
@ArchAngelDDay,
@mallocsys,
@alicanact60, @_godiego_ — congrats!
@busf4ctor &
@monkehack take AI Bug Research honors at Google VRP Mexico.
@yeswehack wins the European Commission’s 4-year bug bounty tender to secure open-source assets.
@Hacker0x01 paid $81M in bounties last year — AI vulns spiking.
@immunefi rolls out new anti-spam rules (Oct 1)
@Bugcrowd opens
@SimpliSafe program (up to $6K)
@TomKuCoin launches KuCoin program (up to $15K).
Google launches a dedicated AI Vulnerability Reward Program (up to $30K) to clarify the scope of AI security findings.
Cloud Software Group /
@NetScaler goes public with a bug bounty on
@Hacker0x01 .
CTFs & events:
@hackthebox_eu x
@Hacker0x01 AI Red Teaming CTF (500 participants)
@bugcrowd Mind Cathedral (50 teams, 300 submissions)
Videos and write-ups from
@NahamSec,
@amrelsagaei,
@ctbbpodcast , and more.
New tools: graphql-cop, HTML-Search-Engine Chrome extension, file_upload_payloads repo, Gemini-API-Key-Exposure-Scanner — handy for recon & CI/CD testing.
Notable writeups & research: RCE guides, Next.js testing, supply-chain attack techniques by
@0xLupin, SSRF/XSS escalation threads, and a leak exposing personal info of Oscar nominees by
@galnagli.
Full links, winners, writeups & tools →
getDisclosed.com
The bug bounty world, curated.