Coinbase awarded a $500k bug bounty

A False HackerOne Report Based on Bard's Hallucination

Login to any user account using other Facebook app access token

HackerOne lays off 12% of its workforce

Node.js HTTP Request Smuggling via Empty Headers Separated by CR

GitHub Access Token Exposure

How Bug Bounty Platform HackerOne Handled Its Own 'Internal Threat' Actor

Playstation confirms chain of 5 vulnerabilities on PS4/PS5

GitHub Account hijack through broken link in developer.twitter.com

Remote Code Execution in Slack desktop apps

XXE on HTTPS://Duckduckgo.com

Slack account takeovers using HTTP Request Smuggling

GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

U.S. Senate Hearing – Data Security and Bug Bounty Programs: Lessons Learned

Prototype pollution attack

European Parliament has approved budget for VLC bug bounty program

Ethical considerations of access to the HackerOne community

Round error issue - produce money for free on itBit bitcoin exchange

Pam-ussh may be tricked into using another logged in user's ssh-agent

Shopify has paid over $300k in security exploit bounties

Nintendo Launches Vulnerability Rewards Program for Nintendo 3DS

“During the investigation we noticed that you placed a shell into our web root”

Imgur disclosed on HackerOne: SSRF in https://imgur.com/vidgif/url

Mårten Mickos: Why I Joined HackerOne as CEO

It's time for security research to be protected under the law

CSRF protection bypass due to Google analytics and weird server cookie parsing

The Wolves of Vuln Street – System Dynamics Model of the 0day Market

$9000 bounty paid for Python bug