# bounty

Published articles for bounty.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## $1 million hacker challenge for Vercel Sandbox

DevFeed: [$1 million hacker challenge for Vercel Sandbox](<https://devfeed.tech/articles/1-million-hacker-challenge-for-vercel-sandbox-769.md>)

Original publisher: [Read original article](<https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox>)

Author: Andy Riancho

Published: 2026-08-18T13:00:00Z

Content type: article

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Vercel](<https://devfeed.tech/topics/vercel.md>), [Firecracker](<https://devfeed.tech/topics/firecracker.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Network](<https://devfeed.tech/topics/network.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [firecracker](<https://devfeed.tech/tags/firecracker.md>), [linux](<https://devfeed.tech/tags/linux.md>), [network](<https://devfeed.tech/tags/network.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [security](<https://devfeed.tech/tags/security.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Vercel announces a two-week public HackerOne challenge offering up to $1 million in total payouts for researchers who can escape Vercel Sandbox isolation. The article explains that Sandbox uses Firecracker microVMs on bare-metal Amazon EC2 hosts, with host-side network controls forming part of the security boundary. Individual reports can receive up to $50,000 for vulnerabilities allowing access to another Vercel tenant's data.

### Source excerpt

Agents need to run untrusted code, and the microVM has become the standard way to do it: a dedicated guest kernel per workload, isolated from the host and from every other workload on the same machine. But recent security research and real-world incidents have revealed that agents running untrusted code do not need to cross a VM boundary to escape containment; they only need one network path the security model failed to account for, which we explained in our post A sandbox without a network boundary is only half a sandbox. Isolation only holds if both sides of it hold: the Firecracker microVM and the host-side network controls. Recently our CTO pointed an open-weight model with no safeguards at Vercel Sandbox. It did not escape, but it mapped the guest kernel, built a VM to reproduce its ideas, and wrote a fuzzer. Defenders have first-mover advantage, but it won't last forever, and the choice is when to test the boundaries (we strongly encourage building a scanning program, which you can do on any budget with an open-source tool like deepsec and AI Gateway). We are proactively choosing to test Vercel Sandbox on our own schedule, not an attacker's, and we are doing it in the open, with the best researchers in the world. So for two weeks, we are paying up to $1,000,000 USD to the researchers who can escape a Vercel Sandbox. The challenge Starting today, Vercel is running a two-week public HackerOne program focused on Vercel Sandbox isolation. Program: Public HackerOne program, open to all eligible researchers Window: Tuesday, August 18 to Tuesday, September 1, 2026, or earlier if the reward pool is exhausted Max per report: $50,000 USD, for a vulnerability that lets a threat actor read or modify another Vercel tenant's data Total pool: Up to $1,000,000 USD in total payouts Bounties are paid per report, scoped to a single root cause, and assigned by Vercel triage based on the maximum demonstrable impact. The full bounty table, detailed scope, and the list of known-dupl

## Burp's new Ambassadors: learn from the people who use Burp Suite everyday

DevFeed: [Burp's new Ambassadors: learn from the people who use Burp Suite everyday](<https://devfeed.tech/articles/burp-s-new-ambassadors-learn-from-the-people-who-use-burp-suite-everyday-7700.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/burps-new-ambassadors-learn-from-the-people-who-use-burp-suite-everyday>)

Author: Fran Hutchings

Published: 2026-07-17T13:35:25Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Mobile Security](<https://devfeed.tech/topics/mobile-security.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>)

Tags: [ambassador](<https://devfeed.tech/tags/ambassador.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [community](<https://devfeed.tech/tags/community.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

PortSwigger introduces four new Burp Ambassadors and highlights their contributions to web application security, including research, education, penetration testing, bug bounty work, community events, and practical Burp Suite workflows.

### Source excerpt

Growing our Burp Ambassador community Meet our newest Burp Ambassadors Katie Paxton-Fear Malek Mohammad Yogesh Tantak James Lester Looking ahead Interested in getting involved? Growing our Burp Ambass

## GPT-5.5 Bio Bug Bounty

DevFeed: [GPT-5.5 Bio Bug Bounty](<https://devfeed.tech/articles/gpt-5-5-bio-bug-bounty-6310.md>)

Original publisher: [Read original article](<https://openai.com/index/bio-bug-bounty>)

Published: 2026-07-09T10:00:00Z

Content type: news

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Jailbreak](<https://devfeed.tech/topics/jailbreak.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [frontier-ai](<https://devfeed.tech/tags/frontier-ai.md>), [gpt](<https://devfeed.tech/tags/gpt.md>), [jailbreak](<https://devfeed.tech/tags/jailbreak.md>), [models](<https://devfeed.tech/tags/models.md>), [openai](<https://devfeed.tech/tags/openai.md>), [safety](<https://devfeed.tech/tags/safety.md>)

### AI overview

OpenAI is turning its GPT-5.5 Bio Bug Bounty into an ongoing private Bio Bounty Program focused on universal jailbreaks against biosafety challenges for frontier models. Rewards for qualifying GPT-5.5 and GPT-5.6 findings have increased from $25,000 to $50,000.

### Source excerpt

Details about the OpenAI Bio Bounty program

## Chainguard Launches Bugcrowd Bug Bounty With Up to $200,000 in Rewards

DevFeed: [Chainguard Launches Bugcrowd Bug Bounty With Up to $200,000 in Rewards](<https://devfeed.tech/articles/we-re-putting-our-security-to-the-test-and-we-want-your-help-13313.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/we-are-putting-our-security-to-the-test-and-we-want-your-help>)

Published: 2026-07-06T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [bugcrowd-bug-bounty](<https://devfeed.tech/tags/bugcrowd-bug-bounty.md>), [chainguard-bug-bounty](<https://devfeed.tech/tags/chainguard-bug-bounty.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [security](<https://devfeed.tech/tags/security.md>), [security-contest](<https://devfeed.tech/tags/security-contest.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard is running a Bugcrowd bug bounty from July 6-27, offering up to $200,000 to researchers who find vulnerabilities in its infrastructure and products.

### Source excerpt

Chainguard launches a Bugcrowd bounty with up to $200K in rewards, inviting researchers to test its infrastructure against real-world attacks.

## PortSwigger partners with Meta Bug Bounty to empower bug hunters with training and Pro licenses

DevFeed: [PortSwigger partners with Meta Bug Bounty to empower bug hunters with training and Pro licenses](<https://devfeed.tech/articles/portswigger-partners-with-meta-bug-bounty-to-empower-bug-hunters-with-training-and-pro-licenses-7734.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/portswigger-partners-with-meta-bug-bounty-to-empower-bug-hunters-with-training-and-pro-licenses>)

Author: Fran Hutchings

Published: 2026-04-07T12:12:07Z

Content type: release

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Web](<https://devfeed.tech/topics/web.md>), [Meta](<https://devfeed.tech/topics/meta.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [education](<https://devfeed.tech/tags/education.md>), [meta](<https://devfeed.tech/tags/meta.md>), [partners](<https://devfeed.tech/tags/partners.md>), [security](<https://devfeed.tech/tags/security.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [training](<https://devfeed.tech/tags/training.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

PortSwigger announces a partnership with Meta Bug Bounty to provide eligible bug hunters with training, learning pathways, and Burp Suite Professional licenses. The initiative aims to improve testing efficiency, help researchers identify high-impact vulnerabilities, and strengthen the global security research community.

### Source excerpt

More power for bug hunters An education-first approach to bug bounty Rewards on Meta's Bug Bounty Platform Our shared vision Ready to get started? We're excited to announce a new partnership with Meta

## VRP 2025 Year in Review

DevFeed: [VRP 2025 Year in Review](<https://devfeed.tech/articles/vrp-2025-year-in-review-19816.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2026/03/vrp-2025-year-in-review.html>)

Author: Kimberly Samra (noreply@blogger.com)

Published: 2026-03-31T16:55:00Z

Content type: article

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Google](<https://devfeed.tech/topics/google.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [google](<https://devfeed.tech/tags/google.md>), [none](<https://devfeed.tech/tags/none.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Google's 2025 Vulnerability Reward Program review marks its 15th anniversary and reports more than $17 million awarded to over 700 security researchers. It also describes a dedicated AI VRP, expanded Chrome rewards for AI-related issues, OSV-SCALIBR patch rewards, and security community events.

### Source excerpt

Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team 2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerability reward program (VRP) has seen constant additions and expansions over the past decade and a half, clearly indicating the value the programs under this umbrella contribute to the safety and security of Google and its users, but also highlighting their acceptance by the external research community, without which such programs cannot function. Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer. This was more evident than ever as we awarded over $17 million (an all-time high and more than 40% increase compared to 2024!) to over 700 researchers based in countries around the globe - across all of our programs. Vulnerability Reward Program 2025 in Numbers Want to learn more about who's reporting to the VRP? Check out our Leaderboard on the Google Bug Hunters site. VRP Highlights in 2025 In 2025 we made a series of changes and improvements to our VRP and related initiatives, and continued to invest in the security research community through a series of focused events: The new, dedicated AI VRP was launched, underscoring the importance of this space to Google and its relevance for external researchers. Previously organized as a part of the Abuse VRP, moving into a dedicated VRP has gone hand in hand with improvements to the rules, offering researchers more clarity on scope and reward amounts. Similarly, the Chrome VRP now also includes reward categories for problems found in AI features. We launched a patch rewards program for OSV-SCALIBR, Google's open source tool for finding vulnerabilities in software dependencies. Contributors are rewarded for providing novel OSV-SCALIBR plugins for inventory, vulne

## Welcome to AI pentesting - add on-demand AI assistance directly to your workflow with new, agentic Burp AI capabilities

DevFeed: [Welcome to AI pentesting - add on-demand AI assistance directly to your workflow with new, agentic Burp AI capabilities](<https://devfeed.tech/articles/welcome-to-ai-pentesting-add-on-demand-ai-assistance-directly-to-your-workflow-with-new-agentic-burp-ai-capabilities-7755.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/welcome-to-ai-pentesting-add-on-demand-ai-assistance-directly-to-your-workflow-with-new-agentic-burp-ai-capabilities>)

Author: Amelia Coen

Published: 2025-09-24T14:17:34Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [tools](<https://devfeed.tech/tags/tools.md>), [validation](<https://devfeed.tech/tags/validation.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [workflow](<https://devfeed.tech/tags/workflow.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

The article introduces agentic Burp AI capabilities that provide on-demand assistance within penetration-testing workflows. Burp AI can explain behavior, suggest attack ideas and payloads, validate findings, analyze request and response data, automate repetitive tasks, and help test for vulnerabilities such as stored XSS while keeping the tester in control.

### Source excerpt

Whether you're navigating a client pentest or chasing a bounty target, even the most experienced testers hit roadblocks, burn time on repetitive tasks, or just want a second opinion. Burp AI is design

## How to join the desync endgame: Practical tips from pentester Tom Stacey

DevFeed: [How to join the desync endgame: Practical tips from pentester Tom Stacey](<https://devfeed.tech/articles/how-to-join-the-desync-endgame-practical-tips-from-pentester-tom-stacey-7724.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/how-to-join-the-desync-endgame-practical-tips-from-pentester-tom-stacey>)

Author: Andrzej Matykiewicz

Published: 2025-09-18T15:51:39Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [guest-post](<https://devfeed.tech/tags/guest-post.md>), [http](<https://devfeed.tech/tags/http.md>), [research](<https://devfeed.tech/tags/research.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This guest post presents practical guidance for joining research into HTTP/1.1 desynchronization vulnerabilities. It discusses HTTP Request Smuggling, two novel desync vulnerability classes, their impact on major CDNs, bug bounty opportunities, and a newer scanning technique intended to identify request-boundary problems.

### Source excerpt

Note: This is a guest post by pentester and researcher, Tom Stacey (@t0xodile). You'd think that after almost 21 years since its initial public discovery, HTTP Request Smuggling would be barely exploi

## Ethereum Announces Four-Week Fusaka Audit Contest

DevFeed: [Ethereum Announces Four-Week Fusaka Audit Contest](<https://devfeed.tech/articles/fusaka-2-000-000-audit-contest-17183.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2025/09/15/fusaka-audit-content>)

Author: Ethereum Protocol Security Research Team

Published: 2025-09-15T00:00:00Z

Content type: release

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [security](<https://devfeed.tech/tags/security.md>), [security-platform](<https://devfeed.tech/tags/security-platform.md>), [smart-contract](<https://devfeed.tech/tags/smart-contract.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Ethereum has launched a four-week audit contest for the Fusaka upgrade, hosted on Sherlock and co-sponsored by Gnosis and Lido. The contest is intended to identify vulnerabilities before they affect the network, with time-limited point multipliers for early valid findings.

### Source excerpt

Today, we are excited to announce the start of the Fusaka audit contest, co-sponsored by Gnosis and Lido, hosted on Sherlock, and running for four weeks from September 15th. The goal is simple: maximize scrutiny of the Fusaka upgrade and surface vulnerabilities before they can impact the network. To...

## Pectra Audit Competition Launches on Cantina

DevFeed: [Pectra Audit Competition Launches on Cantina](<https://devfeed.tech/articles/pectra-audit-competition-launches-on-cantina-17137.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2025/02/21/pectra-audit>)

Author: Protocol Security Research Team

Published: 2025-02-21T00:00:00Z

Content type: release

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [audit](<https://devfeed.tech/tags/audit.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [event](<https://devfeed.tech/tags/event.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Ethereum announces the Pectra Audit Competition on Cantina, running from February 21 to March 24. The competition seeks vulnerabilities in Pectra-specific code before the mainnet hard fork and outlines key Pectra changes, including account features, validator updates, withdrawals, and increased blob capacity.

### Source excerpt

Today, we're excited to announce the Pectra Audit Competition, kicking off on Cantina! This month-long event will run from February 21 to March 24, and we're excited to see what issues the security community can find....

## Bugbounty and Pentests at Neon

DevFeed: [Bugbounty and Pentests at Neon](<https://devfeed.tech/articles/bugbounty-and-pentests-at-neon-5064.md>)

Original publisher: [Read original article](<https://neon.com/blog/bugbounty-and-pentests-at-neon>)

Author: Busra Demir

Published: 2024-11-25T16:43:38Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Database](<https://devfeed.tech/topics/database.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [tenant data protection](<https://devfeed.tech/topics/tenant-data-protection.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [api-security](<https://devfeed.tech/tags/api-security.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [company](<https://devfeed.tech/tags/company.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [launch](<https://devfeed.tech/tags/launch.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [platform](<https://devfeed.tech/tags/platform.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [production](<https://devfeed.tech/tags/production.md>), [security](<https://devfeed.tech/tags/security.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Neon announces a private Bug Bounty Program in partnership with HackerOne and describes three penetration tests that identified and resolved 58 vulnerabilities. The program covers authentication, data protection, API security, production, and staging environments, with rewards based on severity and defined response targets.

### Source excerpt

At Neon, security is at the core of everything we do. Our serverless platform was built with a vision for innovation, but we also know that a commitment to security is paramount. That's why we're excited to announce the launch of our Neon's Bug Bounty Program in partnership with...

## Ethereum Foundation Announces 2025 Internship Program

DevFeed: [Ethereum Foundation Announces 2025 Internship Program](<https://devfeed.tech/articles/announcing-the-2025-ef-internship-program-17121.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2024/11/16/announcing-ef-internship-program>)

Author: EF Protocol Support

Published: 2024-11-16T00:00:00Z

Content type: release

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Development](<https://devfeed.tech/topics/development.md>), [Security](<https://devfeed.tech/topics/security.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [applications](<https://devfeed.tech/tags/applications.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [internship](<https://devfeed.tech/tags/internship.md>), [program](<https://devfeed.tech/tags/program.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The Ethereum Foundation has opened applications for its first formal summer internship program, scheduled for 2025. The approximately 12-week program includes research and development roles, mentorship, and projects related to Ethereum.

### Source excerpt

The 2025 Ethereum Foundation internship applications are open! Both research and development teams have open positions. Applications close on December 9, 2024. The Ethereum Foundation is running its first formal summer internship program in 2025 aimed at nurturing the next generation of Ethereum developers and researchers. In...

## 0Din: A GenAI Bug Bounty Program - Securing Tomorrow's AI Together

DevFeed: [0Din: A GenAI Bug Bounty Program - Securing Tomorrow's AI Together](<https://devfeed.tech/articles/0din-a-genai-bug-bounty-program-securing-tomorrow-s-ai-together-4134.md>)

Original publisher: [Read original article](<https://hacks.mozilla.org/2024/08/0din-a-genai-bug-bounty-program-securing-tomorrows-ai-together/>)

Author: Marco Figueroa

Published: 2024-08-08T18:39:13Z

Content type: article

Language: en

Sources: [Mozilla Hacks - the Web developer blog](<https://devfeed.tech/sources/mozilla-hacks-the-web-developer-blog.md>)

Topics: [genai](<https://devfeed.tech/topics/genai.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [Jailbreak](<https://devfeed.tech/topics/jailbreak.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [coding](<https://devfeed.tech/tags/coding.md>), [featured-article](<https://devfeed.tech/tags/featured-article.md>), [genai](<https://devfeed.tech/tags/genai.md>), [jailbreak](<https://devfeed.tech/tags/jailbreak.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article introduces 0Din, a GenAI bug bounty program focused on identifying and mitigating vulnerabilities in AI systems. It explains the reporting and review process, reward criteria, covered vulnerability types, and participant eligibility.

### Source excerpt

As AI continues to evolve, so do the threats against it. As these GenAI systems become more sophisticated and widely adopted, ensuring their security and ethical use becomes paramount. 0Din is a groundbreaking GenAI bug bounty program dedicated specifically to help secure GenAI systems and beyond. In this blog, you'll learn about 0Din, how it works, and how you can participate and make a difference in securing our AI future. The post 0Din: A GenAI Bug Bounty Program - Securing Tomorrow's AI Together appeared first on Mozilla Hacks - the Web developer blog.

## Shopify's Bug Bounty Program Raises Maximum Payout in 2022

DevFeed: [Shopify's Bug Bounty Program Raises Maximum Payout in 2022](<https://devfeed.tech/articles/shopify-s-bug-bounty-program-raises-maximum-payout-in-2022-1585.md>)

Original publisher: [Read original article](<https://shopify.engineering/shopify-bug-bounty-program-maximum-payout-2022>)

Author: Jenn Newton

Published: 2022-03-22T18:56:46Z

Content type: news

Language: en

Sources: [Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering.md>), [Shopify Engineering - Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering-shopify-engineering.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug](<https://devfeed.tech/tags/bug.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [security](<https://devfeed.tech/tags/security.md>), [shopify](<https://devfeed.tech/tags/shopify.md>)

### AI overview

Shopify announces 2022 changes to its bug bounty program, doubling the maximum CVSS 10.0 reward to $100,000 and classifying several services as Core assets for higher-severity payouts.

### Source excerpt

In 2022, Shopify's Bug Bounty Program is doubling the maximum reward to $100,000 and moving key services into the highest severity level.

## Bug Bounty Findings on BLS Primitives in Beacon Chain Specifications and Clients

DevFeed: [Bug Bounty Findings on BLS Primitives in Beacon Chain Specifications and Clients](<https://devfeed.tech/articles/secured-no-1-16977.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2021/09/09/secured-no-1>)

Author: Antonio Sanso

Published: 2021-09-09T00:00:00Z

Content type: article

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [client](<https://devfeed.tech/topics/client.md>)

Tags: [blockchain](<https://devfeed.tech/tags/blockchain.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [development](<https://devfeed.tech/tags/development.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This first post in a security series examines bug bounty submissions targeting BLS primitives used in the beacon chain and consensus layer. It discusses specification oversights, implementation mistakes, and implementation violations, including issues found through differential fuzzing. The article states that all bugs mentioned had already been fixed.

### Source excerpt

Earlier this year, we launched a bug bounty program focused on finding issues in the beacon chain specification, and/or in client implementations (Lighthouse, Nimbus, Teku, Prysm etc...). The results (and vulnerability reports) have been enlightening as have the lessons learned while patching potential issues. In this new series, we...

## Ethereum 2.0 update: Phase 0 bounties, Schlesi testnet, and v0.12 preparation

DevFeed: [Ethereum 2.0 update: Phase 0 bounties, Schlesi testnet, and v0.12 preparation](<https://devfeed.tech/articles/eth2-quick-update-no-11-16903.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2020/05/06/eth2-quick-update-no-11>)

Author: Danny Ryan

Published: 2020-05-06T00:00:00Z

Content type: news

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Network](<https://devfeed.tech/topics/network.md>), [Security](<https://devfeed.tech/topics/security.md>), [Internet Engineering Task Force (IETF)](<https://devfeed.tech/topics/ietf.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [bug](<https://devfeed.tech/tags/bug.md>), [build](<https://devfeed.tech/tags/build.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [ietf](<https://devfeed.tech/tags/ietf.md>), [release](<https://devfeed.tech/tags/release.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [security](<https://devfeed.tech/tags/security.md>), [standard](<https://devfeed.tech/tags/standard.md>)

### AI overview

This Ethereum 2.0 update announces doubled rewards in the Phase 0 pre-launch bounty program, reports progress on the Schlesi multi-client testnet, and outlines preparation for specification version v0.12.

### Source excerpt

We've all been pretty busy with all the things! I'll try to keep these posts rolling out, but in the meantime, be sure to checkout Ben Edgington's What's New in Eth2 to get your fix. Tune into Ethereal Virtual Summit this Thursday and Friday! It's full of excellent eth2...

## Eth2 Phase 0 audit completed, pre-launch bounty program announced

DevFeed: [Eth2 Phase 0 audit completed, pre-launch bounty program announced](<https://devfeed.tech/articles/eth2-quick-update-no-10-16897.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2020/03/31/eth2-quick-update-no-10>)

Author: Danny Ryan

Published: 2020-03-31T00:00:00Z

Content type: release

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [P2P](<https://devfeed.tech/topics/p2p.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [audit](<https://devfeed.tech/tags/audit.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [p2p](<https://devfeed.tech/tags/p2p.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

This Eth2 update reports the completion of Least Authority's comprehensive audit of the Phase 0 specifications, including patched DoS vectors and further investigation of identified concerns. It also announces a pre-launch bug bounty program with rewards of up to $10,000 and describes efforts to unify eth1 and eth2 communications.

### Source excerpt

Have some fun announcements for y'all this week :) Other than the items below, client teams continue to move toward production. More on that next week! tl;dr Least Authority Phase 0 audit complete Phase 0 Pre-Launch Bounty Program 🐛 Unification of eth1+eth2 communications in the Eth R&D...

## Announcing Ethereum Foundation and Co-Funded Grants

DevFeed: [Announcing Ethereum Foundation and Co-Funded Grants](<https://devfeed.tech/articles/announcing-ethereum-foundation-and-co-funded-grants-16857.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2019/08/26/announcing-ethereum-foundation-and-co-funded-grants>)

Author: Ethereum Foundation

Published: 2019-08-26T00:00:00Z

Content type: release

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Development](<https://devfeed.tech/topics/development.md>), [networking](<https://devfeed.tech/topics/networking.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>), [Security](<https://devfeed.tech/topics/security.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Nim](<https://devfeed.tech/topics/nim.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [beacon](<https://devfeed.tech/tags/beacon.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-fixes](<https://devfeed.tech/tags/bug-fixes.md>), [ecosystem-support-program](<https://devfeed.tech/tags/ecosystem-support-program.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [funding](<https://devfeed.tech/tags/funding.md>), [interoperability](<https://devfeed.tech/tags/interoperability.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [launch](<https://devfeed.tech/tags/launch.md>), [networking](<https://devfeed.tech/tags/networking.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The Ethereum Foundation announces more than $2 million in Foundation-led and co-funded grants for Serenity (Eth2.0) development. Funding supports client implementations, Beacon Chain and testnet work, networking and interoperability, security research, and Lodestar JavaScript development, alongside open research and development bounties.

### Source excerpt

We are today unveiling over $2M USD in Foundation-led and co-funded grant funding aimed at furthering Serenity (Eth2.0) development as we move nearer to the launch of the Beacon Chain....

## Bug Bounty Year in Review 2018

DevFeed: [Bug Bounty Year in Review 2018](<https://devfeed.tech/articles/bug-bounty-year-in-review-2018-1587.md>)

Original publisher: [Read original article](<https://shopify.engineering/shopify-bug-bounty-year-in-review-2018>)

Author: Peter Yaworski

Published: 2018-12-20T18:27:00Z

Content type: article

Language: en

Sources: [Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering.md>), [Shopify Engineering - Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering-shopify-engineering.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Shopify](<https://devfeed.tech/topics/shopify.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [reports](<https://devfeed.tech/tags/reports.md>), [review](<https://devfeed.tech/tags/review.md>), [security](<https://devfeed.tech/tags/security.md>), [shopify](<https://devfeed.tech/tags/shopify.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Shopify's 2018 Bug Bounty year-in-review describes its security program, community of researchers, HackerOne partnership, live hacking event, and improved report triage. Average triage time fell from four days in 2017 to 10 hours in 2018 through a dedicated weekly triager and severity-based validation and escalation.

### Source excerpt

With 2018 coming to a close, we thought it a good opportunity to once again reflect on our Bug Bounty program. At Shopify, our bounty program complements our security strategy and allows us to leverage a community of thousands of researchers who help secure our platform and create a better Shopify user experience. This was the fifth year we operated a bug bounty program, the third on HackerOne and our most successful to date (you can read about last year's results here).

## Solidity Bugfix Release

DevFeed: [Solidity Bugfix Release](<https://devfeed.tech/articles/solidity-bugfix-release-16833.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2018/09/13/solidity-bugfix-release>)

Author: Solidity Team

Published: 2018-09-13T00:00:00Z

Content type: release

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Solidity](<https://devfeed.tech/topics/solidity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [bug](<https://devfeed.tech/tags/bug.md>), [code](<https://devfeed.tech/tags/code.md>), [compiler](<https://devfeed.tech/tags/compiler.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [release](<https://devfeed.tech/tags/release.md>), [research-development](<https://devfeed.tech/tags/research-development.md>)

### AI overview

Solidity 0.4.25 fixes two important bugs, including incorrect results from certain exponentiation operations involving short integer types. Solidity 0.4.22 previously fixed a separate bug that can cause memory corruption when functions return multidimensional fixed-size arrays.

### Source excerpt

The latest version 0.4.25 release of Solidity fixes two important bugs. Another important bug has already been fixed in version 0.4.22 but it was only discovered recently that the bug existed. Note that the Ethereum Foundation runs a bounty program for the code generator part of Solidity....

## A Possible Solution To The Open Source Funding Problem

DevFeed: [A Possible Solution To The Open Source Funding Problem](<https://devfeed.tech/articles/a-possible-solution-to-the-open-source-funding-problem-32225.md>)

Original publisher: [Read original article](<https://bruceeckel.com/2017/09/11/a-possible-solution-to-the-open-source-problem/>)

Author: Bruce Eckel

Published: 2017-09-11T00:00:00Z

Content type: opinion

Language: en

Sources: [Bruce Eckel - Computing Thoughts](<https://devfeed.tech/sources/bruce-eckel-computing-thoughts.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [projects](<https://devfeed.tech/tags/projects.md>), [strategies](<https://devfeed.tech/tags/strategies.md>)

### AI overview

The article discusses the open-source funding problem and considers bounty-based approaches as a possible partial solution. It argues that enabling people to get paid for developing open-source software is important to the future of the field.

### Source excerpt

William Gross has posted Give Away Your Code, But Never Your Time, a potential and/or partial solution to the problem of funding open source projects, which I offered a solution for here. I've since heard from people pointing out projects that have actually used the "bounty" approach - I was unintentionally describing something that already exists. We've been solving all these other problems around open source, but not the essential one: how can people get paid for developing open-source software.

## Solidity optimizer bug

DevFeed: [Solidity optimizer bug](<https://devfeed.tech/articles/solidity-optimizer-bug-16806.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2017/05/03/solidity-optimizer-bug>)

Author: Martin Swende

Published: 2017-05-03T15:21:57Z

Content type: article

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [bug](<https://devfeed.tech/topics/bug.md>), [Solidity](<https://devfeed.tech/topics/solidity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>)

Tags: [2017](<https://devfeed.tech/tags/2017.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug](<https://devfeed.tech/tags/bug.md>), [code](<https://devfeed.tech/tags/code.md>), [release](<https://devfeed.tech/tags/release.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article describes a Solidity optimizer bug affecting bytecode constants. The bug could generate routines that failed to recreate the original constant under specific conditions, and it was patched in Solidity 0.4.11 on 2017-05-03. The article notes that static analysis found no occurrence in deployed contract code, while cautioning that this does not guarantee none exist.

### Source excerpt

A bug in the Solidity optimizer was reported through the Ethereum Foundation Bounty program, by Christoph Jentzsch. This bug is patched as of 2017-05-03, with the release of Solidity 0.4.11....

## Security Alert - Mist can be vulnerable when navigating to malicious DApps

DevFeed: [Security Alert - Mist can be vulnerable when navigating to malicious DApps](<https://devfeed.tech/articles/security-alert-mist-can-be-vulnerable-when-navigating-to-malicious-dapps-16784.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2016/10/27/security-alert-mist-can-vulnerable-navigating-malicious-dapps>)

Author: Fabian Vogelsteller

Published: 2016-10-27T11:12:05Z

Content type: news

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [browser](<https://devfeed.tech/tags/browser.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [files](<https://devfeed.tech/tags/files.md>), [security](<https://devfeed.tech/tags/security.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A security alert reports that Mist versions 0.8.6 and lower exposed low-level APIs that malicious DApps or webpages could use to access the computer's filesystem, delete files, launch protocol handlers, and obtain sensitive information. Users are advised to upgrade Mist and avoid untrusted webpages. Ethereum Wallet is not affected because it cannot load external DApps.

### Source excerpt

Mist leaks some low level APIs, which Dapps could use to gain access to the computer's file system and read/delete files. This would only affect you if you navigate to an untrusted Dapp that knows about these vulnerabilities and specifically tries to attack users. Upgrading Mist is highly recommended to prevent exposure...

## A Model To Fund Open-Source Projects

DevFeed: [A Model To Fund Open-Source Projects](<https://devfeed.tech/articles/a-model-to-fund-open-source-projects-32215.md>)

Original publisher: [Read original article](<https://bruceeckel.com/2016/06/20/a-model-to-fund-open-source-projects/>)

Author: Bruce Eckel

Published: 2016-06-20T00:00:00Z

Content type: opinion

Language: en

Sources: [Bruce Eckel - Computing Thoughts](<https://devfeed.tech/sources/bruce-eckel-computing-thoughts.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [business](<https://devfeed.tech/tags/business.md>), [funding](<https://devfeed.tech/tags/funding.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [releases](<https://devfeed.tech/tags/releases.md>)

### AI overview

The article proposes funding open-source projects through release bounties: users who need the newest release pay toward a set bounty, while previous releases remain free. Once the bounty is met, the new release becomes free.

### Source excerpt

Synopsis Place a bounty on the next release of an open-source project. Until the bounty is met, those who need/want the newest release must pay an amount in order to get it. Previous releases remain free. Once the bounty is met, the new release becomes free. The Problem of Funding I think open-source is one of the most important cultural and business innovations produced (so far) by the computing and network revolution.

[Next page](<https://devfeed.tech/tags/bounty.md?cursor=WyIyMDE2LTA2LTIwVDAwOjAwOjAwKzAwOjAwIiwgIjVlNGZhMzU1LWNiNzMtNDcwMS1hNzUwLTE4YWZkYjU0MDc5MSJd>)