Topic
HackerOne

Automated Pentesting and BAS: How AI Systems Like XBOW Outpace Human Researchers in Vulnerability Discovery
Vulnerabilities & Exploits
Recon in Bug Bounty: Spotting Anomalies Instead of Chasing Known Vulnerability Patterns
Vulnerabilities & Exploits
From Scanner Overload to Manual Insight: A Bug Bounty Hunter's Journey
OtherWordPress Patches Critical Core Vulnerability CVE-2026-87902 Affecting All Versions from 4.7.0
WordPress has released patches for a critical vulnerability in the platform's core code, tracked as CVE-2026-87902 with a CVSS score of 9.2. The flaw impacts every version from 4.7.0 through 7.1.1, meaning virtually all unpatched installations remain exposed. Because the issue resides in the base system rather than plugins or themes, even sites without any extensions installed are at risk. The vulnerability allows an unauthenticated attacker to load arbitrary PHP files from outside theme directories, which can lead to remote code execution on certain server configurations. The bug was privately reported in July by researcher Robert Ressl through HackerOne and disclosed publicly on 22 September, with no confirmed exploitation observed so far. Administrators are urged to apply the updates immediately and keep automatic updates enabled.
AI Disrupts White Hat Ecosystem: 8000 Viewers Join Live Debate on SRC Closures and Security Industry Future
A live stream hosted by AikerWorld and HackingClub drew nearly 8000 viewers as nine security experts debated the impact of AI on white hat communities following the closure of a major financial sector SRC and HackerOne's shift to mandatory real-name submissions. Hu Xiaona, founder of the communities and 360 VulnCloud executive, described the changes as a structural wave that devalues routine vulnerability submissions while pushing practitioners toward AI Forward Deployed Engineer roles. Xiong Yong argued that AI lowers attack costs yet forces enterprises to treat security as essential rather than optional. Other speakers including Yang Wei, Wei Yongqiang, and Jia Yu examined pricing pressure, the need for human oversight during AI-driven testing, and the cyclical nature of security budgets. The discussion converged on the view that AI eliminates low-skill tool-based hunting but elevates complex research and defensive engineering skills. Participants highlighted risks such as un-audited AI actions deleting production data and warned that SRC platforms are moving from open crowdsourcing to curated, real-name models.
HackerOne Ends Anonymous Era for Bug Bounty Hunters with Mandatory ID Verification
HackerOne has introduced compulsory identity verification for all researchers submitting reports to paid bug bounty programs, effective August 1. The policy requires users to complete KYC checks through Estonian firm Veriff by uploading government-issued ID and performing a live selfie, with annual renewals. Vulnerability Disclosure Programs remain open to anonymous participants, but any researcher seeking monetary rewards must now reveal their identity. The move follows similar steps by Bugcrowd and Intigriti and is driven by anti-money laundering and cross-border payment regulations. Researchers in high-surveillance regions and newcomers face new barriers, while the platform argues the change improves report quality and enterprise trust. H1 Clear adds an extra criminal background check layer for elite participants.
Rent, Don't Build: Penetration Testing, Vulnerability Management, and Bug Bounty as a Service
The fifth installment in the Vulnerability Management for Beginners series explores three outsourcing models that allow organizations to avoid building their own infrastructure for vulnerability management. Pentest as a Service, VM as a Service, and bug bounty programs each offer distinct advantages in speed, coverage, and cost while shifting operational burdens to specialized providers. The article details how automated and manual penetration testing differ in depth and scope, why white-box scanning inside the network yields more accurate results than black-box perimeter tests, and how bug bounty platforms like HackerOne and Standoff Bug Bounty have scaled dramatically in Russia and globally. It also covers practical requirements such as proving asset ownership, establishing triage processes, setting realistic SLAs, and handling sensitive data risks when using external services. Benchmarks from providers, updated EPSS metrics, CISA KEV catalogs, and the latest FSTEC methodology are presented as tools for better prioritization. The piece concludes with legal and operational caveats for Russian companies adopting these models in 2025.
Memory Theft Attack Tricks Claude AI into Exfiltrating User Personal Secrets Through Web Navigation
Security researcher Ayush Paul demonstrated how Claude's memory system can be exploited to leak sensitive user data including full names, employers, and security question answers without any user interaction beyond a normal query. The attack leverages Claude's web_fetch tool and a specially crafted website that forces the AI to navigate an alphabetical link structure to spell out private information stored in conversation summaries and conversation_search results. By disguising the exfiltration as a Cloudflare-style authentication challenge for a fictional coffee shop, the researcher bypassed Claude's safety mechanisms and achieved reliable data leakage. The technique works because web_fetch allows navigation through links present on previously fetched pages, enabling the construction of an on-the-fly 'keyboard' of alphabetical paths. After responsible disclosure via HackerOne, Anthropic implemented a partial mitigation by disabling external link navigation in web_fetch, though the underlying memory exposure risk remains for other connected tools and services.