What Happened to HackerOne?
HackerOne has changed significantly from the bug bounty platform many researchers knew in the late 2010s.
Its current direction is increasingly centered around Hai, AI-assisted triage, vulnerability validation, agentic testing, continuous testing and CTEM.
But the question isn't simply whether HackerOne uses AI. It's how researcher submissions, security intelligence and AI-driven workflows fit together, and what that means for the role and value of human vulnerability researchers.
I dug into HackerOne's history, funding, Live Hacking Events, pricing shift, AI architecture, researcher-data controversy and current product strategy.
https://thecybersecguru.com/analysis/what-happened-to-hackerone/
#HackerOne #BugBounty #InfoSec #CyberSecurity #AppSec #VulnerabilityResearch #AISecurity #CybersecurityResearch #EthicalHacking #Pentesting #AgenticAI #CTEM #SecurityResearch #BugBountyHunters #ApplicationSecurity
About This Hashtag
#vulnerabilityresearch
8 posts
Last used Aug 10
#vulnerabilityresearch
8 posts· Last used Aug 10
Heute gab es eine Bestätigung, über die ich mich sehr freue: Meine Bewerbung für das Cyber Verification Program von Anthropic war erfolgreich.
Das mag im großen Kontext für manche vielleicht nach einer Randnotiz klingen, aber für mich ist es ein starkes Zeichen, dass die eigene Arbeit ernst genommen wird. Ich freue mich auf die kommenden technischen Analysen und bedanke mich für das entgegengebrachte Vertrauen.
#CyberSecurity #InfoSec #AI #VulnerabilityResearch
Last night I "discovered" a vulnerability in a very widely used open-source tool. The tool is nearly 40 years old, and the vulnerability is at least 28 years old.
Interestingly, Apple has a fix included that dates it back to 2008, but it appears for whatever reason the fix never made it to upstream.
Result? Everyone else is vulnerable today. I am not pointing fingers here, but clearly something went wrong.
I've now reported the issue upstream, which will hopefully eventually lead to a fix being distributed to every affected platform.
I am not going to disclose the details of the vulnerability right now, even though the fix has been public for a very, very long time now. As far as I can tell, most Linux and BSD systems are vulnerable right now, so letting coordinated disclosure happen only makes sense.
#infosec #cybersecurity #vulnerabilityresearch
RE: https://infosec.exchange/@hnsec/116923239649243702
My #Semgrep C/C++ ruleset is ready for prime time again!
Grab it before our new robot overlords take over the field of #VulnerabilityResearch entirely 🤖
Quoting
Our Technical Director @raptor@infosec.exchange just shipped v2.0.0 of his #Semgrep C/C++ ruleset — now officially included in the @semgrep@infosec.exchange registry.
Marco built this ruleset back in 2022 to speed up C/C++ #VulnerabilityResearch, and it's since become a go-to reference, featured in several guides and toolkits.
This release brings new detections, fewer false positives, and better performance, all put to the test on real-world source code and binary firmware.
https://hnsecurity.it/blog/my-semgrep-c-cpp-ruleset-is-ready-for-prime-time-again/
Open quoted postOur Technical Director @raptor@infosec.exchange just shipped v2.0.0 of his #Semgrep C/C++ ruleset — now officially included in the @semgrep@infosec.exchange registry.
Marco built this ruleset back in 2022 to speed up C/C++ #VulnerabilityResearch, and it's since become a go-to reference, featured in several guides and toolkits.
This release brings new detections, fewer false positives, and better performance, all put to the test on real-world source code and binary firmware.
https://hnsecurity.it/blog/my-semgrep-c-cpp-ruleset-is-ready-for-prime-time-again/
𝗛𝗼𝘄 𝗱𝗲𝗲𝗽 𝗰𝗮𝗻 𝘆𝗼𝘂𝗿 𝗵𝗲𝗮𝗽 𝗿𝗲𝗿𝗲𝗮𝗿𝗰𝗵 𝗴𝗼?
“Class teaches exploitation and gives exact, in‑depth heap knowledge. By far the best in‑person training I’ve done.”
Build a research‑first understanding, practise hands‑on manipulation (& 𝗠𝗲𝗺𝗼𝗿𝗶𝗴𝗮𝗺𝗶), detect and analyse corruptions, craft robust strategies and chain primitives into exploits. Applies to 32‑ and 64‑bit targets.
Seats limited: https://www.corelan-training.com
#CorelanHeap #HeapExploitation #VulnerabilityResearch
🧠 Aprende a pensar como un ciberatacante para construir defensas web con un elevado nivel de ciberseguridad 🔒
♾ Miércoles 15, Viernes 17, Miércoles 22 y Viernes 24 de Julio
✔️ De 8:00 pm a 11:00 pm (UTC -05:00)
🔈 WhatsApp: https://wa.me/51949304030
🧲 Info: https://www.reydes.com/archivos/cursos/Curso_Hacking_Aplicaciones_Web.pdf
#WebSecurity #AppSec #OWASP #Penetesting #VulnerabilityResearch #ZedAttackProxy
AI is changing vulnerability research and exploit development but it's only as effective as the expertise behind it.
Corelan training combines deep technical knowledge with practical AI-assisted workflows. Learn to analyze vulnerabilities, develop reliable exploits, improve your prompting, automate repetitive tasks, and validate every result with a rigorous methodology. AI doesn't replace expertise. It amplifies it.
https://bit.ly/corelan-training
#Corelan #VulnerabilityResearch #ExploitDev #AISkill
You've seen all posts