To Kara, Alex, and Michiel — Your Researchers Are Leaving
Bug bounty platforms never humanized researchers or triage. Now they're drowning in AI slop and wondering why their best people are leaving.
Reporting bugs, working with vendors, and life inside bug bounty programmes.
Bug bounty platforms never humanized researchers or triage. Now they're drowning in AI slop and wondering why their best people are leaving.
A Firefox-only reflected XSS on wwwb.search.billmelater.com, achieved by closing out of a style attribute and injecting a fresh script element, which the vendor classified as out of scope.
WP Live Chat Support, MyLiveChat and Provide Support all accepted stored cross-site scripting during a 2014 customer install.
Chrome resolves and executes a script URL written as http: followed by any number of backslashes. Firefox does not, and that difference can slip past pattern-matching XSS filters, closed by Chromium as wontfix.
A path traversal issue on Prezi's map.prezi.com subdomain, fixed within two days of reporting and rewarded with a $1,000 bounty.
Reflected cross-site scripting across 160 German tax office websites, disclosed via heise.de and forwarded to CERT-Bund for coordinated remediation.