1. CVE-2023-54391 and beyond: excavating silent patches and the attacker-defender information gap vulnerability | 2026-09-09 07:11 | CVE-2023-54391 | yeswehack.com | original ↗ | #ai-security | #exploit | #vulnerability-disclosure
2. The latest from HackerOne blog | 2026-09-01 14:53 | hackerone.com | original ↗ | #ai-security | #bug-bounty | #rce
3. The hidden cost of agentic pentesting blog | 2026-08-27 14:41 | bugcrowd.com | original ↗ | #ai-security | #bug-bounty | #pentesting
4. Report Smarter, Not Harder: HackerOne's Case for Better CIRCIA Rules blog | 2026-08-20 14:08 | hackerone.com | original ↗ | #bug-bounty | #cisa | #compliance
5. How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years blog | 2026-08-04 14:45 | portswigger.net | original ↗ | #pentesting | #agentic-ai | #burp-suite
6. Rickrolling the World Cup, unleashing AI across Google, 0-click stored XSS on Next.js – ethical hacker roundup blog | 2026-07-21 08:36 | yeswehack.com | original ↗ | #ai-security | #vulnerability-research | #github
7. Authentication Bypass in the default configuration phpBB vulnerability | Critical | 2026-07-04 00:00 | CVE-2026-48611 | aikido.dev | original ↗ | #ai-security | #featured | #account-takeover
8. What Is a Bug Bounty Program and How Does It Work? blog | 2026-07-06 11:12 | hackenproof.com | original ↗ | #bug-bounty | #security-community | #security-training
9. Introducing Patch the Planet blog | 2026-06-22 16:50 | blog.trailofbits.com | original ↗ | #ai-security | #supply-chain | #vulnerability-management
10. Patch the Planet: HackerOne Joins OpenAI's Daybreak Initiative to Secure Critical Open-Source Software blog | 2026-06-22 13:38 | hackerone.com | original ↗ | #ai-security | #bug-bounty | #open-source
11. Shynet | VERSION 0.13.1 blog | 2026-06-18 00:00 | bishopfox.com | original ↗ | #appsec | #vulnerability-research | #security-audit
12. 3 myths about VDPs for state and local governments research | 2026-06-16 12:00 | bugcrowd.com | original ↗ | #bug-bounty | #vulnerability-management | #cisa
13. Pi.Alert - Unauthenticated SQL Injection research | 2026-06-14 07:32 | CVE-2026-44886 | projectblack.io | original ↗ | #vulnerability-research | #sql-injection | #vulnerability-disclosure
14. HackenProof guide to Vulnerability Disclosure Policy blog | 2026-06-16 16:25 | hackenproof.com | original ↗ | #bug-bounty | #vulnerability-management | #compliance
15. Pandora NFT: BugFix Review blog | 2026-06-11 10:26 | hackenproof.com | original ↗ | #web3 | #vulnerability-research | #defi
16. NEAR Rewards $1.8 Million to Ethical Hackers at HackenProof blog | 2026-06-11 10:19 | hackenproof.com | original ↗ | #bug-bounty | #web3 | #vulnerability-disclosure
17. How to Create a Vulnerability Disclosure Program for Crypto Business blog | 2026-06-11 07:01 | hackenproof.com | original ↗ | #web3 | #compliance | #vdp
18. What verified users say about running a vulnerability disclosure program with Bugcrowd blog | 2026-05-21 12:00 | bugcrowd.com | original ↗ | #ai-security | #bug-bounty | #vulnerability-management
19. What is a Bug Bounty Program? blog | 2026-04-30 13:09 | bugcrowd.com | original ↗ | #bug-bounty | #bugcrowd | #crowdsourced-security
20. Vulnerability Disclosure Policy: What is It & Why is it Important? blog | 2026-04-30 07:00 | bugcrowd.com | original ↗ | #bug-bounty | #vulnerability-management | #vdp
21. Roundcube XSS chained with cookie tossing for full inbox access blog | 2026-04-21 00:00 | aikido.dev | original ↗ | #ai-security | #attack-chains | #web-security
22. Bug bounty isn’t dead, but the old model is breaking blog | 2026-04-13 00:00 | aikido.dev | original ↗ | #ai-security | #bug-bounty | #open-source
23. 3 Principles for Modern VDPs: How AWS Keeps Vulnerability Disclosure Working at Massive Scale blog | 2026-04-10 01:08 | hackerone.com | original ↗ | #bug-bounty | #cloud | #aws
24. Europe’s New AI Security Standard: What It Means for Vulnerability Disclosure and AI Red Teaming blog | 2026-03-25 19:35 | hackerone.com | original ↗ | #ai-security | #red-teaming | #compliance
25. EU Cyber Resilience Act: Preparing Your VDP for 2026 Reporting Requirements blog | 2026-03-17 18:02 | hackerone.com | original ↗ | #bug-bounty | #compliance | #vdp
26. Carelessness versus craftsmanship in cryptography blog | 2026-02-18 12:00 | blog.trailofbits.com | original ↗ | #vulnerability-research | #open-source | #cryptography
27. LLM bug hunters lack intuition, ‘security teams will consolidate visibility’ in 2026, EU Cyber Act vuln disclosure revisions – offsec roundup for CISOs blog | 2026-02-16 12:48 | yeswehack.com | original ↗ | #ai-security | #post-quantum | #vulnerability-disclosure
28. Project Black is now a CVE Numbering Authority (CNA) research | 2026-02-11 22:07 | projectblack.io | original ↗ | #vulnerability-management | #vulnerability-research | #vulnerability-disclosure
29. Hacker opinion piece: How lazy hacking killed cURL’s bug bounty blog | 2026-02-05 13:00 | bugcrowd.com | original ↗ | #ai-security | #bug-bounty | #zero-day
30. Hacking An AI Children's Toy: Remote Access to Every Conversation blog | 2026-01-29 00:00 | josephthacker.com | original ↗ | #ai-security | #data-exposure | #iot