# bug bounty

Published articles for bug bounty.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

DevFeed: [PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting](<https://devfeed.tech/articles/phantomraven-an-llm-generated-information-stealer-developed-for-bug-bounty-hunting-30904.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/>)

Author: Maddie Stewart

Published: 2026-09-16T13:36:43.658349Z

Content type: news

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [npm](<https://devfeed.tech/topics/npm.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [llm](<https://devfeed.tech/tags/llm.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [threat-hunting-intel](<https://devfeed.tech/tags/threat-hunting-intel.md>)

### AI overview

CrowdStrike reports that a financially motivated bug bounty hunter developed and distributed PhantomRaven, a JavaScript-based information stealer through npm. The company assesses with high confidence that a large language model was used to write the malware and says the operator likely used it to identify bug bounty opportunities.

### Source excerpt

CrowdStrike identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript-based information stealer PhantomRaven.

## August 2026 Security Release

DevFeed: [August 2026 Security Release](<https://devfeed.tech/articles/august-2026-security-release-3138.md>)

Original publisher: [Read original article](<https://nextjs.org/blog/august-2026-security-release>)

Author: Sebastian Silbermann

Published: 2026-08-25T18:00:00Z

Content type: release

Language: en

Sources: [Next.js Blog](<https://devfeed.tech/sources/next-js-blog.md>)

Topics: [Next.js](<https://devfeed.tech/topics/next-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Next.js released versions 16.3.3 and 15.5.24 to address critical vulnerabilities, including unauthenticated remote code execution through AVIF image optimization and on Windows-hosted servers. The patched releases disable AVIF optimization until an upstream fix is propagated.

### Source excerpt

The August 2026 security release for Next.js is now available

## Update: August Next.js Security Release

DevFeed: [Update: August Next.js Security Release](<https://devfeed.tech/articles/update-august-next-js-security-release-3270.md>)

Original publisher: [Read original article](<https://nextjs.org/blog/nextjs-security-release-august-2026-update>)

Author: Sebastian Silbermann

Published: 2026-08-25T15:00:00Z

Content type: news

Language: en

Sources: [Next.js Blog](<https://devfeed.tech/sources/next-js-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [frameworks](<https://devfeed.tech/tags/frameworks.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [update](<https://devfeed.tech/tags/update.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Next.js is advancing its August security release to address two critical vulnerabilities in a single update and recommends that users upgrade when patched versions are available.

### Source excerpt

Next.js is moving the August security release forward to August 25, 2026.

## Upcoming Next.js August Security Release

DevFeed: [Upcoming Next.js August Security Release](<https://devfeed.tech/articles/upcoming-next-js-august-security-release-3288.md>)

Original publisher: [Read original article](<https://nextjs.org/blog/upcoming-nextjs-security-release-august-2026>)

Author: Sebastian Silbermann

Published: 2026-08-20T18:00:00Z

Content type: release

Language: en

Sources: [Next.js Blog](<https://devfeed.tech/sources/next-js-blog.md>)

Topics: [Next.js](<https://devfeed.tech/topics/next-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Next.js is preparing a scheduled August 2026 security release addressing critical-severity vulnerabilities. The release is expected to include patched versions 16.3.3 and 15.5.24, with a full advisory and upgrade instructions.

### Source excerpt

Next.js is preparing a scheduled August security release for August 26, 2026.

## How We're Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees

DevFeed: [How We're Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees](<https://devfeed.tech/articles/how-we-re-building-scam-alert-on-whatsapp-with-end-to-end-encryption-and-verifiability-guarantees-129.md>)

Original publisher: [Read original article](<https://engineering.fb.com/2026/08/12/security/how-were-building-scam-alert-whatsapp/>)

Author: Chris Wiltz

Published: 2026-08-12T13:00:28Z

Content type: article

Language: en

Sources: [Engineering at Meta](<https://devfeed.tech/sources/engineering-at-meta.md>)

Topics: [End-to-End Encryption](<https://devfeed.tech/topics/end-to-end-encryption.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [Security](<https://devfeed.tech/topics/security.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [user-control](<https://devfeed.tech/tags/user-control.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>)

### AI overview

An early technical overview of WhatsApp's optional Scam Alert feature, which uses a small on-device machine learning model to classify potential scam messages while keeping message content on the device. The article explains how the design preserves end-to-end encryption through local processing, avoids automatic reporting, gives users control, and supports independent security review during a limited Beta rollout.

### Source excerpt

WhatsApp is committed to helping people stay safe while protecting the privacy of their messages. As scam tactics evolve -- from impersonation to social engineering to AI-generated lures -- we're always evolving as well, so that our protections stay ahead of scammers while protecting people's personal messages with end-to-end encryption. Today, we're sharing an early [...] Read More... The post How We're Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees appeared first on Engineering at Meta.

## Can AI invent new attack techniques? New research from James Kettle and PortSwigger Research

DevFeed: [Can AI invent new attack techniques? New research from James Kettle and PortSwigger Research](<https://devfeed.tech/articles/can-ai-invent-new-attack-techniques-new-research-from-james-kettle-and-portswigger-research-7702.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/can-ai-invent-new-attack-techniques-new-research-from-james-kettle-and-portswigger-research>)

Author: Kieron Hughes

Published: 2026-08-12T09:04:45Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [AI research agents](<https://devfeed.tech/topics/ai-research-agents.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [http](<https://devfeed.tech/tags/http.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [research](<https://devfeed.tech/tags/research.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

PortSwigger Research describes the HTTP Terminator, an autonomous system used to generate and test new HTTP desync attack techniques against authorized bug-bounty targets. The research emphasizes that human expertise remained important in steering follow-on discoveries.

### Source excerpt

We already know AI can find vulnerabilities. James Kettle, PortSwigger's Director of Research, wanted to answer a harder question: can an autonomous system invent genuinely new attack techniques? To f

## Security update: Redis response to the Kimi K3 vulnerability claims

DevFeed: [Security update: Redis response to the Kimi K3 vulnerability claims](<https://devfeed.tech/articles/security-update-redis-response-to-the-kimi-k3-vulnerability-claims-4849.md>)

Original publisher: [Read original article](<https://redis.io/blog/security-update-redis-response-to-the-kimi-k3-vulnerability-claims/>)

Author: Curtis Means

Published: 2026-07-27T00:00:00Z

Content type: news

Language: en

Sources: [Redis Blog](<https://devfeed.tech/sources/redis-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [model](<https://devfeed.tech/tags/model.md>), [redis](<https://devfeed.tech/tags/redis.md>), [releases](<https://devfeed.tech/tags/releases.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [tech](<https://devfeed.tech/tags/tech.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Redis says the public Kimi K3 claims currently document three already-known vulnerabilities, not a verified list of 19 zero days. It released or expedited fixes and advises users to patch and follow security practices.

### Source excerpt

Last week, researchers posted on X that they had used the Kimi K3 AI model to identify vulnerabilities in Redis, including a claim involving 19 zero day vulnerabilities. We became aware of this research through the public posts and immediately review...

## Burp's new Ambassadors: learn from the people who use Burp Suite everyday

DevFeed: [Burp's new Ambassadors: learn from the people who use Burp Suite everyday](<https://devfeed.tech/articles/burp-s-new-ambassadors-learn-from-the-people-who-use-burp-suite-everyday-7700.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/burps-new-ambassadors-learn-from-the-people-who-use-burp-suite-everyday>)

Author: Fran Hutchings

Published: 2026-07-17T13:35:25Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Mobile Security](<https://devfeed.tech/topics/mobile-security.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>)

Tags: [ambassador](<https://devfeed.tech/tags/ambassador.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [community](<https://devfeed.tech/tags/community.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

PortSwigger introduces four new Burp Ambassadors and highlights their contributions to web application security, including research, education, penetration testing, bug bounty work, community events, and practical Burp Suite workflows.

### Source excerpt

Growing our Burp Ambassador community Meet our newest Burp Ambassadors Katie Paxton-Fear Malek Mohammad Yogesh Tantak James Lester Looking ahead Interested in getting involved? Growing our Burp Ambass

## Next.js Security Release and Our Next Patch Release

DevFeed: [Next.js Security Release and Our Next Patch Release](<https://devfeed.tech/articles/next-js-security-release-and-our-next-patch-release-3266.md>)

Original publisher: [Read original article](<https://nextjs.org/blog/next-security-release-program>)

Author: Josh Story

Published: 2026-07-13T12:00:00Z

Content type: release

Language: en

Sources: [Next.js Blog](<https://devfeed.tech/sources/next-js-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [llm](<https://devfeed.tech/tags/llm.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [process](<https://devfeed.tech/tags/process.md>), [release](<https://devfeed.tech/tags/release.md>), [release-schedule](<https://devfeed.tech/tags/release-schedule.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Next.js is formalizing a predictable security release program with advance monthly notices, while retaining ad-hoc patches for urgent or actively exploited vulnerabilities.

### Source excerpt

Next.js is moving to a formal security release process

## GPT-5.5 Bio Bug Bounty

DevFeed: [GPT-5.5 Bio Bug Bounty](<https://devfeed.tech/articles/gpt-5-5-bio-bug-bounty-6310.md>)

Original publisher: [Read original article](<https://openai.com/index/bio-bug-bounty>)

Published: 2026-07-09T10:00:00Z

Content type: news

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Jailbreak](<https://devfeed.tech/topics/jailbreak.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [frontier-ai](<https://devfeed.tech/tags/frontier-ai.md>), [gpt](<https://devfeed.tech/tags/gpt.md>), [jailbreak](<https://devfeed.tech/tags/jailbreak.md>), [models](<https://devfeed.tech/tags/models.md>), [openai](<https://devfeed.tech/tags/openai.md>), [safety](<https://devfeed.tech/tags/safety.md>)

### AI overview

OpenAI is turning its GPT-5.5 Bio Bug Bounty into an ongoing private Bio Bounty Program focused on universal jailbreaks against biosafety challenges for frontier models. Rewards for qualifying GPT-5.5 and GPT-5.6 findings have increased from $25,000 to $50,000.

### Source excerpt

Details about the OpenAI Bio Bounty program

## Chainguard Launches Bugcrowd Bug Bounty With Up to $200,000 in Rewards

DevFeed: [Chainguard Launches Bugcrowd Bug Bounty With Up to $200,000 in Rewards](<https://devfeed.tech/articles/we-re-putting-our-security-to-the-test-and-we-want-your-help-13313.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/we-are-putting-our-security-to-the-test-and-we-want-your-help>)

Published: 2026-07-06T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [bugcrowd-bug-bounty](<https://devfeed.tech/tags/bugcrowd-bug-bounty.md>), [chainguard-bug-bounty](<https://devfeed.tech/tags/chainguard-bug-bounty.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [security](<https://devfeed.tech/tags/security.md>), [security-contest](<https://devfeed.tech/tags/security-contest.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard is running a Bugcrowd bug bounty from July 6-27, offering up to $200,000 to researchers who find vulnerabilities in its infrastructure and products.

### Source excerpt

Chainguard launches a Bugcrowd bounty with up to $200K in rewards, inviting researchers to test its infrastructure against real-world attacks.

## How I hunt for vulnerabilities with AI

DevFeed: [How I hunt for vulnerabilities with AI](<https://devfeed.tech/articles/how-i-hunt-for-vulnerabilities-with-ai-5283.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/how-i-hunt-for-vulnerabilities-with-ai>)

Author: Tsvetan Stoychev

Published: 2026-06-26T11:24:26Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [Security](<https://devfeed.tech/topics/security.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [claude](<https://devfeed.tech/tags/claude.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [code](<https://devfeed.tech/tags/code.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [github-copilot](<https://devfeed.tech/tags/github-copilot.md>), [guest-post](<https://devfeed.tech/tags/guest-post.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This guest post explains how an experienced software engineer used GitHub Copilot with Claude Opus and Gemini models to investigate vulnerabilities in the large C++ ClickHouse codebase. The workflow used AI to search code, generate hypotheses, and accelerate validation in local environments, leading to several real vulnerability reports.

### Source excerpt

I'm an experienced software engineer, but I'm not a seasoned bug bounty hunter. I used GitHub Copilot in combination with Claude Opus and Gemini models to search for vulnerabilities in the ClickHouse codebase, generate hypotheses, and speed up validation.

## The Wonders of AI: We Are Retiring Our Bug Bounty Program

DevFeed: [The Wonders of AI: We Are Retiring Our Bug Bounty Program](<https://devfeed.tech/articles/the-wonders-of-ai-we-are-retiring-our-bug-bounty-program-6048.md>)

Original publisher: [Read original article](<https://turso.tech/blog/the-wonders-of-ai>)

Author: Glauber Costa

Published: 2026-05-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Turso Blog](<https://devfeed.tech/sources/turso-blog.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Turso](<https://devfeed.tech/topics/turso.md>), [SQLite](<https://devfeed.tech/topics/sqlite.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [data](<https://devfeed.tech/topics/data.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [concurrency](<https://devfeed.tech/tags/concurrency.md>), [data](<https://devfeed.tech/tags/data.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [sqlite](<https://devfeed.tech/tags/sqlite.md>), [testing](<https://devfeed.tech/tags/testing.md>), [turso](<https://devfeed.tech/tags/turso.md>)

### AI overview

Turso is retiring its $1,000 data-corruption bug bounty after an influx of low-quality pull requests overwhelmed maintainers. The article explains the tension between keeping an open contribution model and protecting review capacity, while outlining Turso's extensive testing practices and their limits.

### Source excerpt

For almost a year now, Turso has had a program that pays $1,000 for any bug that can be demonstrated to lead to data corruption. Today, we are retiring this program.

## Rails Security, AI, and IBB

DevFeed: [Rails Security, AI, and IBB](<https://devfeed.tech/articles/rails-security-ai-and-ibb-39005.md>)

Original publisher: [Read original article](<https://tenderlovemaking.com/2026/05/06/rails-security-ai-and-ibb/>)

Published: 2026-05-06T17:31:54Z

Content type: opinion

Language: en

Sources: [Aaron Patterson](<https://devfeed.tech/sources/aaron-patterson.md>)

Topics: [Rails](<https://devfeed.tech/topics/rails.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [rails](<https://devfeed.tech/tags/rails.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A Rails team member reflects on the Internet Bug Bounty program, describing how AI-generated low-quality security reports overwhelmed the team and contributed to the program stopping new submissions and bounty payments. The change also removed incentives for legitimate researchers and left Rails handling payment-related questions.

### Source excerpt

For quite a few years the Rails project has been working with the Internet Bug Bounty (IBB). The IBB is an organization that awarded cash to security researchers that reported issues to OSS projects participating in the IBB. For quite a while I wasn't certain about my feelings toward the program because I felt like cash rewards could incentivize low quality reports as well as encourage reporters to "haggle" about the severity of a particular bug (the IBB paid more when the bug was more severe). In the beginning that certainly was the case. We were fielding many low quality reports, and people were haggling over severity. But the program evolved, and despite the never-ending haggling, I felt it did more good (rewarding security researchers) than bad (forcing the security team to wade through low quality reports). That is, until AI came along. Sometime in 2025 our team started getting inundated with low quality AI generated reports. I know for sure this wasn't unique to just our team as well. Anyway, AI lowered the barrier to generate reports, so we were back in the era of wading through low quality reports. Only this time, the low quality reports were masquerading as high quality reports. AI made it easy to turn a bullshit problem into something that looked legit, and since there's a possibility of money involved people tried to take advantage of the situation. We even had a report where someone forgot to delete the AI generated output and just uploaded the report as-is with the following text: ## ✅ READY TO SUBMIT! *All information prepared for professional Rails bug bounty submission.* *Expected Outcome:* Rails Team Response: 1-2 weeks Fix Development: 2-8 weeks Security Release: 8-12 weeks IBB Bounty: $1,040-1,600 (80% of $1,300-2,000) *Next Step:* Copy information above into HackerOne form and submit! I enjoy using AI, but I really don't like AI being used on me. But that's not what this post is about. Recently the IBB stopped accepting new submissions. In other

## Introducing the official Burp Ambassador Program

DevFeed: [Introducing the official Burp Ambassador Program](<https://devfeed.tech/articles/introducing-the-official-burp-ambassador-program-7733.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/introducing-the-official-burp-ambassador-program>)

Author: Fran Hutchings

Published: 2026-04-16T13:24:25Z

Content type: news

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [ambassador](<https://devfeed.tech/tags/ambassador.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [community](<https://devfeed.tech/tags/community.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [extension](<https://devfeed.tech/tags/extension.md>)

### AI overview

PortSwigger announces the Burp Ambassador Program, a community initiative for experienced Burp users to help shape Burp Suite and share application-security knowledge.

### Source excerpt

Why we're launching the program What it means to be a Burp Ambassador What we're aiming for Our Burp Ambassadors Alan Levy Corey Ball Federico Dotta Rana Khalil Tib3rius Looking ahead Get Involved - B

## PortSwigger partners with Meta Bug Bounty to empower bug hunters with training and Pro licenses

DevFeed: [PortSwigger partners with Meta Bug Bounty to empower bug hunters with training and Pro licenses](<https://devfeed.tech/articles/portswigger-partners-with-meta-bug-bounty-to-empower-bug-hunters-with-training-and-pro-licenses-7734.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/portswigger-partners-with-meta-bug-bounty-to-empower-bug-hunters-with-training-and-pro-licenses>)

Author: Fran Hutchings

Published: 2026-04-07T12:12:07Z

Content type: release

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Web](<https://devfeed.tech/topics/web.md>), [Meta](<https://devfeed.tech/topics/meta.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [education](<https://devfeed.tech/tags/education.md>), [meta](<https://devfeed.tech/tags/meta.md>), [partners](<https://devfeed.tech/tags/partners.md>), [security](<https://devfeed.tech/tags/security.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [training](<https://devfeed.tech/tags/training.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

PortSwigger announces a partnership with Meta Bug Bounty to provide eligible bug hunters with training, learning pathways, and Burp Suite Professional licenses. The initiative aims to improve testing efficiency, help researchers identify high-impact vulnerabilities, and strengthen the global security research community.

### Source excerpt

More power for bug hunters An education-first approach to bug bounty Rewards on Meta's Bug Bounty Platform Our shared vision Ready to get started? We're excited to announce a new partnership with Meta

## Security Bug Bounty Program Paused Due to Loss of Funding

DevFeed: [Security Bug Bounty Program Paused Due to Loss of Funding](<https://devfeed.tech/articles/security-bug-bounty-program-paused-due-to-loss-of-funding-2416.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties>)

Published: 2026-04-02T12:00:00Z

Content type: news

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [developers](<https://devfeed.tech/tags/developers.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Node.js has paused its security bug bounty program because the external funding source for monetary rewards was discontinued. Security reporting through HackerOne continues, but vulnerability reports are no longer eligible for bounty payouts.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## VRP 2025 Year in Review

DevFeed: [VRP 2025 Year in Review](<https://devfeed.tech/articles/vrp-2025-year-in-review-19816.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2026/03/vrp-2025-year-in-review.html>)

Author: Kimberly Samra (noreply@blogger.com)

Published: 2026-03-31T16:55:00Z

Content type: article

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Google](<https://devfeed.tech/topics/google.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [google](<https://devfeed.tech/tags/google.md>), [none](<https://devfeed.tech/tags/none.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Google's 2025 Vulnerability Reward Program review marks its 15th anniversary and reports more than $17 million awarded to over 700 security researchers. It also describes a dedicated AI VRP, expanded Chrome rewards for AI-related issues, OSV-SCALIBR patch rewards, and security community events.

### Source excerpt

Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team 2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerability reward program (VRP) has seen constant additions and expansions over the past decade and a half, clearly indicating the value the programs under this umbrella contribute to the safety and security of Google and its users, but also highlighting their acceptance by the external research community, without which such programs cannot function. Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer. This was more evident than ever as we awarded over $17 million (an all-time high and more than 40% increase compared to 2024!) to over 700 researchers based in countries around the globe - across all of our programs. Vulnerability Reward Program 2025 in Numbers Want to learn more about who's reporting to the VRP? Check out our Leaderboard on the Google Bug Hunters site. VRP Highlights in 2025 In 2025 we made a series of changes and improvements to our VRP and related initiatives, and continued to invest in the security research community through a series of focused events: The new, dedicated AI VRP was launched, underscoring the importance of this space to Google and its relevance for external researchers. Previously organized as a part of the Abuse VRP, moving into a dedicated VRP has gone hand in hand with improvements to the rules, offering researchers more clarity on scope and reward amounts. Similarly, the Chrome VRP now also includes reward categories for problems found in AI features. We launched a patch rewards program for OSV-SCALIBR, Google's open source tool for finding vulnerabilities in software dependencies. Contributors are rewarded for providing novel OSV-SCALIBR plugins for inventory, vulne

## Introducing the OpenAI Safety Bug Bounty program

DevFeed: [Introducing the OpenAI Safety Bug Bounty program](<https://devfeed.tech/articles/introducing-the-openai-safety-bug-bounty-program-6635.md>)

Original publisher: [Read original article](<https://openai.com/index/safety-bug-bounty>)

Published: 2026-03-25T00:00:00Z

Content type: news

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [data](<https://devfeed.tech/tags/data.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [openai](<https://devfeed.tech/tags/openai.md>), [safety](<https://devfeed.tech/tags/safety.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

OpenAI launches a Safety Bug Bounty program for reporting AI abuse and safety risks, including agentic prompt injection, data exfiltration, proprietary-information exposure, and account or platform integrity issues.

### Source excerpt

OpenAI launches a Safety Bug Bounty program to identify AI abuse and safety risks, including agentic vulnerabilities, prompt injection, and data exfiltration.

## PortSwigger X Intigriti: Burp Suite Professional licenses up for grabs with this new collaboration

DevFeed: [PortSwigger X Intigriti: Burp Suite Professional licenses up for grabs with this new collaboration](<https://devfeed.tech/articles/portswigger-x-intigriti-burp-suite-professional-licenses-up-for-grabs-with-this-new-collaboration-7736.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/portswigger-x-intigriti-burp-suite-professional-licenses-up-for-grabs-with-this-new-collaboration>)

Author: Fran Hutchings

Published: 2026-03-11T10:36:26Z

Content type: news

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerability-disclosure](<https://devfeed.tech/tags/vulnerability-disclosure.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

PortSwigger and Intigriti announced a collaboration that awards eligible bug bounty researchers a six-month Burp Suite Professional license after reaching 400 reputation points on Intigriti.

### Source excerpt

At PortSwigger, we're always looking for ways to enable the world to secure the web, and today we're excited to take that mission a step further. We're pleased to announce a new collaboration bringing

## Keycloak's Bug Bounty Program on YesWeHack

DevFeed: [Keycloak's Bug Bounty Program on YesWeHack](<https://devfeed.tech/articles/keycloak-s-bug-bounty-program-on-yeswehack-31742.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/01/bugbounty-yes-we-hack>)

Author: Alexander Schwartz

Published: 2026-01-16T00:00:00Z

Content type: news

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [eu](<https://devfeed.tech/tags/eu.md>), [iam](<https://devfeed.tech/tags/iam.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak announces its public bug bounty program on YesWeHack as part of an EU-sponsored initiative. The program is currently paused while submissions are reviewed after receiving many submissions.

### Source excerpt

As a Cloud Native Computing Foundation (CNCF) project, Keycloak is the open-source IAM backbone for countless applications. This is your chance to secure a core piece of the cloud-native ecosystem in this public bug bounty program!. We are proud to be part of this EU sponsored initiative. Projects like ours fuel a lot of public and private infrastructure in the EU and worldwide. Thank you for choosing our project for this initiative to help us to improve and provide secure services to our users! We received a lot of good submissions to the program. While we sort out the submissions, the program is paused.

## Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI

DevFeed: [Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI](<https://devfeed.tech/articles/can-burp-ai-hack-a-website-cybermaddy-explores-the-new-agentic-capabilities-in-burp-ai-7704.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/can-burp-ai-hack-a-website-cybermaddy-explores-the-new-agentic-capabilities-in-burp-ai>)

Author: Amelia Coen

Published: 2025-10-22T13:15:24Z

Content type: news

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [llm](<https://devfeed.tech/tags/llm.md>), [sql](<https://devfeed.tech/tags/sql.md>), [testing](<https://devfeed.tech/tags/testing.md>), [video](<https://devfeed.tech/tags/video.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web](<https://devfeed.tech/tags/web.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

A video examines Burp AI's agentic capabilities for ethical web-security testing, including its use in Repeater to identify SQL injection, XSS, and insecure configurations.

### Source excerpt

In her latest video, CyberMaddy dives into the world of AI-driven ethical hacking, exploring how Burp AI performs in Repeater when tasked with finding web vulnerabilities like SQL injection, cross-sit

## The future of pentesting is Human x AI, and it's already in Burp Suite Professional

DevFeed: [The future of pentesting is Human x AI, and it's already in Burp Suite Professional](<https://devfeed.tech/articles/the-future-of-pentesting-is-human-x-ai-and-it-s-already-in-burp-suite-professional-7743.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/the-future-of-pentesting-is-human-x-ai-and-its-already-in-burp-suite-professional>)

Author: Andrzej Matykiewicz

Published: 2025-10-07T13:17:41Z

Content type: opinion

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-tools](<https://devfeed.tech/tags/ai-tools.md>), [automation](<https://devfeed.tech/tags/automation.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that AI-assisted penetration testing is already widespread, while human expertise remains essential. It presents Burp AI in Burp Suite Professional as a human-controlled tool for summarizing data, iterating payloads, scaffolding proofs of concept, and helping testers identify complex vulnerabilities such as account takeover.

### Source excerpt

The latest Hacker-Powered Security Report from HackerOne makes one thing clear: AI-assisted pentesting isn't a future trend; it's today's reality. In HackerOne's 2025 report, 70% of surveyed researche

## Hacking smarter with Burp AI: NahamSec puts Burp AI to the test

DevFeed: [Hacking smarter with Burp AI: NahamSec puts Burp AI to the test](<https://devfeed.tech/articles/hacking-smarter-with-burp-ai-nahamsec-puts-burp-ai-to-the-test-7710.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/hacking-smarter-with-burp-ai-nahamsec-puts-burp-ai-to-the-test>)

Author: Andrzej Matykiewicz

Published: 2025-10-01T14:31:40Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [features](<https://devfeed.tech/tags/features.md>), [free](<https://devfeed.tech/tags/free.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [video](<https://devfeed.tech/tags/video.md>), [youtube](<https://devfeed.tech/tags/youtube.md>)

### AI overview

NahamSec demonstrates how Burp AI fits into a real bug bounty and security testing workflow, including Repeater, Scanner follow-up, and recorded logins. The AI features run on demand within PortSwigger's secure AI infrastructure. Burp Suite Professional users receive 10,000 free AI credits.

### Source excerpt

Bug bounty legend, NahamSec, has taken Burp AI for a spin. If you're curious how Burp AI fits into a real workflow, his new video is the perfect place to start. Watch on YouTube Burp AI was built to a

[Next page](<https://devfeed.tech/tags/bug-bounty.md?cursor=WyIyMDI1LTEwLTAxVDE0OjMxOjQwKzAwOjAwIiwgImU3MDQ3NmVlLTA3ZGMtNGMzMy05OGUwLTA5NDA0MDdhOGVkMiJd>)