Tag

Bug Bounty

All articles tagged with #bug bounty

technology5 months ago

AI Slop Threatens Open-Source and Security Bounties

AI-generated low-quality reports, known as AI slop, are flooding cybersecurity bug bounty programs, leading to false positives and wasted resources. Experts suggest investing in AI-powered filtering systems to improve report accuracy, with some companies developing hybrid human-AI triage solutions. The problem highlights the challenges of AI hallucinations in critical security processes.

technology6 months ago

Meta Resolves Bug Risking User AI Content Privacy

Meta fixed a security vulnerability that could have allowed users to access others' AI prompts and responses, with the bug being privately disclosed by security researcher Sandeep Hodkasia who received a $10,000 bounty. The flaw involved predictable prompt identifiers that could be manipulated to view private data, but Meta confirmed it was fixed in January with no evidence of exploitation.

technology1 year ago

Microsoft Unveils $4M 'Zero Day Quest' for AI and Cloud Security

Microsoft has announced Zero Day Quest, an in-person hacking event aimed at enhancing AI and cloud security, with $4 million in potential awards for identifying high-impact security flaws. This initiative builds on Microsoft's bug bounty program and offers researchers direct access to Microsoft AI engineers and the AI Red Team. The event, set for 2025 at Microsoft's Redmond headquarters, is part of Microsoft's broader security transformation efforts, emphasizing transparency and collaboration in addressing vulnerabilities.

technology1 year ago

Apple Denies Bug Bounty to Kaspersky Lab

Apple declined to pay a bug bounty to Kaspersky Lab after the Russian cybersecurity firm disclosed four zero-day vulnerabilities in iPhone software, which were allegedly used to spy on Kaspersky employees and Russian diplomats. Kaspersky suggested the vulnerabilities might have been state-sponsored, but Apple denied any collaboration with governments for spying purposes. The refusal comes amid heightened tensions between the US and Russia following the invasion of Ukraine.

technology1 year ago

Bugcrowd Raises $102M, Reaches $1 Billion Valuation

Bugcrowd, a platform that connects organizations with a database of over 500,000 hackers for bug bounty programs, has secured $102 million in equity funding led by General Catalyst, with previous backers Rally Ventures and Costanoa Ventures also participating. The company plans to use the funding to expand operations in the U.S. and beyond, potentially through M&A, and to enhance its platform's functionality, which includes bug bounty programs, penetration testing, and attack surface management. Bugcrowd has seen significant growth, with over 40% annual revenue increase and now has over 1,000 customers and "well over" 500,000 hackers.

cybersecurity2 years ago

"Uncovering Google Hacks for Sports and Profit in 2023"

Google is inviting hackers to participate in a capture the flag (CTF) competition, with the top eight teams qualifying for the Hackceler8 competition in Tokyo later this year, where a prize pot of over $32,000 is up for grabs. The CTF will consist of various challenges, with points awarded for each successful completion. Google has also launched a new ethical hacking program, the Mobile Vulnerability Reward Program (VRP), aimed at uncovering vulnerabilities in Android 'first party' applications, with rewards ranging from $750 to $30,000.

ai2 years ago

OpenAI CEO addresses concerns over GPT-5 training and AI pause

OpenAI CEO Sam Altman confirmed that the company is not currently training GPT-5 and is instead focusing on improving GPT-4. Reddit forums are being flooded with spam generated by ChatGPT bots, leaving moderators struggling to deal with the rising volume of spam. OpenAI has launched a bug bounty program, offering up to $20,000 to developers who discover vulnerabilities, bugs, and security flaws in its AI products. Twitter has reportedly purchased around 10,000 GPUs to develop generative AI models, and Elon Musk has hired engineers from DeepMind to build a rival ChatGPT product that will generate text considered less politically correct.

cybersecurity2 years ago

Google Issues Emergency Fix for Critical Chrome Vulnerability Affecting Billions of Users

Google has released an emergency update for Chrome to fix a zero-day vulnerability that can be exploited by a malicious webpage to run arbitrary code in the browser. The vulnerability is present in Chrome for desktop versions prior to 112.0.5615.121. Meanwhile, Western Digital is being extorted by miscreants who claim to have stolen around 10 terabytes of internal data from the company, including customer and employee information. In response, Google and other tech industry actors have announced a project to create a legal environment that's more favorable for good-faith security researchers, plus another to help fund legal representation for researchers caught in a lawsuit.

technology2 years ago

OpenAI Launches Bug Bounty Program for ChatGPT, Offering Up to $20,000 for Vulnerability Reports.

OpenAI has launched a bug bounty program for its AI services, including ChatGPT, offering rewards ranging from $200 to $20,000 for vulnerabilities found. However, the program excludes rewards for jailbreaking ChatGPT or causing it to generate malicious code or text. OpenAI notes that such "model safety issues" require broader approaches and should be submitted via the company's model feedback page. Last month, a hacker revealed 80 "secret plugins" for the ChatGPT API, prompting some to suggest that a paid bug bounty program could help catch such vulnerabilities in the future.

technology2 years ago

"OpenAI's ChatGPT Bug Bounty Program offers up to $20,000 for reporting vulnerabilities"

OpenAI has launched a bug bounty program offering up to $20,000 to users who report vulnerabilities in its AI systems. The rewards will be based on the severity of the bugs reported, starting from $200 per vulnerability. The program invites researchers to review certain functionality of ChatGPT and the framework of how OpenAI systems communicate and share data with third-party applications. The move comes after ChatGPT was banned in Italy for a suspected breach of privacy rules.