Search/netscape
Vendor

netscape

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
navigator
Connections
24 relationships
Will AI Kill the Bug Bounty Industry?
AI is disruptive. Anthropic’s Claude Mythos model, and its successors, promise to be even more disruptive: they could threaten the existing bug bounty and/or in-house offensive security industries. AI has been widely adopted by both cybersecurity attackers and defenders. Attackers use it to help find bugs and craft attacks from sophisticated social engineering through to developing exploit and malware code. Defenders use it to help detect attacks in progress, detect deepfakes, and help code new software, and for bug bounty hunters and offensive security practitioners, to unearth bugs to fix them before they can be exploited. So far, AI has proven to be a force multiplier rather than a position replacement. Mythos threatens to alter this balance. The evolution of bug bounty programs Bug bounties and pentesting are in a state of flux. That’s nothing new: everything in cybersecurity is constantly in flux. But the Mythos arrival may provide the most rapid flux in offensive security yet. A bounty is a reward. ‘Dead or alive’, was an early 19th-century US tagline. That concept still survives, but with law enforcement now offering bounties for information on live cybercriminals. A bug bounty is a reward for finding a bug not a person. In 1983, Hunter & Ready offered a free Volkswagen Beetle car (commonly known as a Bug) as the reward for finding a computer bug in its VRTX operating system. The new tagline was ‘Get a bug if you find a bug’. The concept of bug bounties had arrived and began to expand from the 1990s: Netscape in 1995; IDefence introducing the middleman concept in 2002 (any person could report any bug to any vendor); Mozilla for Firefox in 2004, Google in 2010, and Facebook in 2011. The HackerOne (with Kara Sprague as CEO) and Bugcrowd (co-founded by Casey Ellis) bug-bounty platforms were established in 2012, followed by YesWeHack in 2015, and Intigriti (Inti De Ceukelaire) in 2016. These are the four primary bounty platforms. Throughout the 2010s the concept expanded and many more companies began to offer bug bounties. By 2022, bounty hunter Youssef Samouda was able to tell SecurityWeek, “With Meta and Google, I make around $400,000 per year.” At the end of 2022, AI in the form of LLMs became generally available, and by late 2024 and early 2025 the modern concept of autonomous agentic AI began to take center stage. By June 2025, autonomous offensive security firm XBOW, had achieved #1 position in HackerOne’s leaderboard. The history of bug bounties shows a consistent combination of expansion with an increasing use of automation and artificial intelligence – which brings us to today. In-house offensive security has followed a similar path but driven by salary rather than reward. Bug bounty today Cassim Khouani (known online as Aituglo and listed in the top 30 Hackers on YesWeHack) wrote The state of Bug Bounty in 2026, published on April 13, 2026. In it, he describes using Claude to aid discovery. Overnight, it discovered ten bugs. “Sounds great on paper. Except half of them were duplicates, and the rest took weeks to get triaged because the report queue on that program had become unmanageable. Welcome to bug bounty in 2026.” He believes bug bounty as we know it today is dying. “What comes next can be better, if we play it right.” Everybody, he suggests, is using one or other form of AI to search for bugs, 24/7 without getting tired. It succeeds, but with side effects: “We end up in a constant mental fog, jumping from one tmux pane to another, switching from one program to the next.” And the bounty platforms themselves suffer from so many new AI-assisted submissions, with triaging and payments taking longer. Companies paying bounties are also suffering with more bug reports, some of poor quality and some critical. “More and more companies are stepping back from bug bounty,” he writes, “while others [such as Google] increase their rewards or change their policy.” Note that after Khouani wrote this in mid-April 2026, Google lowered its Chrome bug bounties and raised its Android bounties on April 30, 2026, citing AI as the cause for both. This is flux with its foot on the pedal: rapid change but not necessarily for the better. “The bug bounty of 2024 is dead. The one in 2026 is a different sport. The hunters who will make it are not those who launch the most agents, but those who know what to look for and where to look. AI is a multiplier, not a replacement.” This was written by Khouani based on his experience of using Claude to assist in bug finding. But then along came Claude Mythos, announced almost at the same moment he published his article. Anthropic’s claims for Mythos going forward suggest the future of AI is more than just a force multiplier. Mythos discovering vulnerabilities Mythos reportedly performs better than any other AI model in finding zero day bugs. “Over the past few weeks, we have used Claude Mythos Preview to identify thousands of zero-day vulnerabilities (that is, flaws that were previously unknown to the software’s developers),” announced Anthropic on April 7, 2026, “many of them critical, in every major operating system and every major web browser, along with a range of other important pieces of software.” In May 2026, Anthropic said its Mythos Preview had identified more than 23,000 potential vulnerabilities after scanning thousands of open-source software projects. Anthropic is apparently so concerned about its ability to find unfound bugs that it has released Mythos Preview to major software providers, allowing them to find and fix their own vulnerabilities (Project Glasswing) before the model becomes generally available. The CSA is equally concerned, having published a paper titled, “The ‘AI Vulnerability Storm’: Building a ‘Mythos-ready’ Security Program”, in which it recommends: “Introduce AI agents to the cyber workforce across the board, enabling defenders to match attackers speed and begin closing the gap.” Fed Chair Powell and Treasury Secretary Bessent met with the heads of major US banks to discuss the cyber risks that may be introduced by Mythos; Reuters has reported ‘Banking industry scrambles for Anthropic’s Mythos as global regulators review risks’; and the media has been full of wild, weird, and wonderful reporting. But one area has had little reporting so far: if Mythos is capable of finding bugs and developing exploit chains so rapidly, what effect will this have on the value and future of the existing bug bounty and offensive security industries? Organizations could just point Mythos at their software and find the bugs without needing to pay bounties or employ expensive pentesters and red teams. The future of bug bounty and offensive security Bug bounty and offensive security are not going away; but both must adapt to a new reality. AI is like sniping: the projectile and its effect may be autonomous, but it still needs a human to aim and pull the trigger. Complete autonomy is still in the future, and that human involvement will remain for years to come. It’s the speed of delivery and the accuracy that has changed. Keep Calm and Carry On: Mythos is not revolutionary Tod Beardsley, VP of security research at runZero, counsels that Mythos should be viewed in the historical concept of an industry barely 30 years old: any advance will seem huge and disruptive while it’s happening. “To be blunt, I don’t think Mythos is fundamentally different or the ‘YOU MUST BUY THIS’ security tooling that Anthropic’s marketing would like us to believe. It’s better tooling, for sure…” But, he adds, “To think that this (or any) model is so fundamentally powerful, dangerous, and revolutionary that you’d be a fool to not buy is to ride along with the classic FUD-based marketing that so often colors cybersecurity marketing… This is just another step on the road to better understanding the risk profile of your particular network.” Richard Ford, CTO at Integrity360, agrees with the need to stay calm but adds, ‘be ready to adapt’. “Anthropic’s own system card shows that this level of performance relied on uncensored models, extended compute, and heavy resampling. In other words, this is not yet a real-world scenario.” Nevertheless, he adds, “Bug bounty programs and human-led testing rely on expertise and time. AI will start to reshape that, although areas like business logic will still depend on human understanding.” It’s adaptation, not replacement, says Chris Payne, VP of forward deployed cyber engineers at Sevii. “Discovery accelerates for everyone, but the real bottleneck has always been investigation and remediation. The defenders who win will pair agentic AI with strong governance so they can investigate, hunt, and remediate at machine speed and endless scale, which will close the gap attackers are widening as we speak.” Jon David, co-founder and MD at NR Labs, agrees with this. The power of Mythos and future AI will allow attackers to find and exploit vulnerabilities faster than defenders can fix them. “But if we leverage AI in the same capacity, it also allows us to find and patch the vulnerabilities before they’re public in production. We must just make sure we’re using the same capabilities as the attackers on ourselves before they do.” This should ensure the continuance of in-house offensive security teams. Bounty hunters and bounty platforms have a slightly different problem to solve: participating companies are likely to become reluctant to pay bounties for an increasing volume of existing but largely irrelevant bug slop already found by hunters and their AI agents, and likely to increase with Mythos. “The widely used Curl project ended its HackerOne program in January 2026 because over 95% of submissions were AI-generated junk,” comments Melissa Bischoping, head of threat research & intelligence at Tanium. “HackerOne [also] paused the Internet Bug Bounty in March, explicitly citing an imbalance between AI-assisted discovery and remediation capacity. Mythos makes this worse by an order of magnitude.” The need for adaptation. Evolving AI increases the speed of discovery and decreases the time to exploitation. Kara Sprague, CEO at HackerOne, points out this is not the gap meant in the CSA report. “The gap they are describing isn’t the gap from discovery to exploitation; it’s clear that it has already collapsed. The gap they are referring to is the operational gap between discovery and remediation: organizations still patch on human timelines, manage risk through quarterly assessments and run remediation through change processes that were never designed for AI-velocity threats.” AI-assisted discovery has flooded programs with low-to-mid-severity findings that maintainers cannot absorb. This will increase with Mythos. “The incentives of such bounty programs need to be rebalanced to favor remediation, which is now the key constraint,” she continues. “Vulnerability findings often sit for a long time before remediation, and this trend will continue as the volume increases. It then becomes a question of prioritizing learning from mistakes rather than focusing on individual issues as that approach hasn’t been scalable and certainly won’t be as these advanced models become more distributed,” adds Shlomie Liberow, founder at aisy.ai, and formerly head of hacker R&D at HackerOne. Bounty platforms are already strained by the number of bugs being discovered. And corporations are unable to keep pace with existing patch levels. What is required is the ability to prioritize high severity bugs over low value bugs, and incentives to prioritize high severity over low value will be built into the programs. The longer view. Corporate options for vulnerability detection remain primarily third-party bounty hunters or in-house offensive security teams. The best option will be governed by whichever adopts the latest technology functionality faster and more intelligently. “Today, frontier model providers (like Anthropic) make AI abundantly cheap to use, reducing the cost of vulnerability research,” suggests Aaron Sant Miller, VP and AI lead for Booz Allen’s Integrated Cyber Business. “If organizations increasingly choose to bring this function in-house, you can expect the bug bounty industry to take a hit. Conversely, bounty hunters may find AI reduces their own cost and time – we may see more bounties executed per month, at a lower cost per bounty. Today’s balancing act will be shaped by adoption.” It may be different tomorrow. The current cost of AI is being eaten by the frontier model developers, and the price to users is artificially low. Once the market has been hooked, the developers may increase their prices to reflect the true market cost. When that happens, organizations will reconsider outsourcing again. “Once AI usage costs begin to reflect their true operating costs, the cost of bug discovery will normalize; organizations and hunters alike will have to determine the fair market price for vulnerability discovery,” he continues. “Overall, in-house security teams that readily adopt AI and evolve their workflows will be more resilient to the disruption.” Sprague agrees that the market for vulnerability hunting is already changing, but she notes, “The total value of the bounty market is growing, not shrinking. High-severity, business-logic and AI-specific vulnerability research (for example, prompt injection, model extraction, adversarial manipulation) is paying more than ever, because very few researchers can do it well.” For in-house offensive teams, she says, “Red teaming was already evolving beyond ‘can we get in’ toward mapping business process fraud paths, executive targeting, third-party compromise chains, privileged identity abuse across SaaS estates. Mythos can’t model your business. It can’t tell you that the real crown jewel isn’t in the codebase at all.” She sees continuous AI-executed adversarial testing with human expertise woven throughout. “Novel attack paths, business logic vulnerabilities and the creative lateral thinking that turns a low-severity finding into a crown jewel compromise still require human ingenuity. AI raises the floor; it doesn’t replace the ceiling.” Summary AI is changing the rules for human vulnerability hunters, but not replacing the requirement. AI can find a never-ending volume of bugs – they will always exist, in both old and new software. But this new AI-discovered volume of bugs, with many of them being low severity, ultimately inconsequential slop, has highlighted the real problem. It’s not finding the bugs (that hasn’t been a problem for years); it’s distinguishing the meat from the slop with rapid remediation. AI is not good at this. It requires human knowledge and ingenuity. In-house human offensive security, using AI but not relying on it, can do this well – and the value of in-house detection and remediation will remain. External bounty hunting will be most impacted, but will continue to offer a valuable service if the bounty paid can be refocused on critical bugs and remediation. This will offer a valuable alternative for those companies that find employment of a permanent in-house team to be too costly. Vulnerability hunting, like every other aspect of cybersecurity, is subject to new technology. And like every other aspect of cybersecurity, the advice to practitioners remains the same: keep calm, adapt, and carry on. Related: Cyber Insights 2026: Offensive Security; Where It Is and Where It’s Going Related: OpenAI Launches Bug Bounty Program for Abuse and Safety Risks Related: Microsoft Bug Bounty Program Expanded to Third-Party Code
securityweek.comJun 9, 2026extracted
CISO Conversations: Aimee Cardwell
Aimee Cardwell started her professional career at Netscape, went on to become a VP of engineering at American Express, and CISO at UnitedHealth Group. She is now CISO in Residence at Transcend. Entry into cybersecurity Cardwell started at Netscape as a product manager rather than product developer. “I tried, but I just wasn’t very good at coding.” She implies her introduction to cybersecurity came from dating Netscape’s head of security and finding herself in the SOC at 4:00 am “chasing down script kiddies in the late ’90s.” From there, “I had a delightful career as a CIO – not a CISO – in financial services companies.” This included VP and Eng/Unit CIO at American Express, and CIO at Optum Financial Services. Optum is part of the UnitedHealth Group. UHG promoted her to CISO, which became her first role as a CISO. It should be no surprise that she believes most modern CISOs need to be technologists as well as businesspeople, people managers and security experts. She did this without any relevant academic background. “I have no university degree. I have built my career through just learning and exploring and a deep curiosity – no college degree at all.” From team member to team leader Learning about computing and security, however, does not a leader make – and the making of a leader is always an interesting topic. “You have to want to solve problems with people, instead of, or alongside, solving problems with code,” she suggests. ‘Most engineers enjoy solving problems; that’s why we’re interested in the field in the first place. It took me a while to realize that solving problems with people was just as much fun, if not, as in my case, more fun. That expands into a desire to build a team to help solve those problems.” That’s the first part. “The second requirement is a strategic outlook. Strategy is one of those things that’s hard to explain, but you know it when you see it. I think when you’re focused on solving a problem, it’s sometimes hard to lift your gaze and see the larger view. So, what are we trying to build? How are we moving the company forward? Is this a risk that’s worth taking? Is there a way that I could do this faster or cheaper? Is there a quicker mitigation that isn’t canonically pure, but is going to still achieve the right goal for the results of the company?” For the CISO, tactics and strategy are not an either/or option. A CISO requires skill in both. The difficulty is encapsulated in the old saying, ‘Can’t see the wood for the trees’ (better known in the US as ‘Can’t see the forest for the trees’), which was included in John Heywood’s compilation of English language proverbs published way back in 1546. Today, applied to the CISO role, it implies that too much focus on the trees (tactics) can reduce perspective on the overall forest health (strategy). But at the same time, you cannot simply focus on the strategy since a single failed tactic, like the bad apple in the barrel, can spread to endanger the strategic forest. Cardwell gives a pertinent illustration. She was asked by another CISO, “How do you manage a team comprising thousands of people?” She replied, “You need a really solid team of individuals. If one is weak, you’ll spend a disproportionate amount of time in that person’s area, potentially micromanaging, potentially dragging out the process of trying to make that individual be stronger. So, I think individual tactics can have a huge impact on overall strategy – imagine your weak tree or bad apple was the head of your incident response. That would be a disaster.” To combine both a tactical and strategic understanding, she focuses on an application of the T-shaped management approach: deep knowledge of individual tactics with a widespread view of overall strategy. One team rather than a collection of different experts The security team is pivotal to a successful cybersecurity posture. There are two elements, not quite conflicting but not necessarily complementary, to the making of a successful team. Each person must be the most expert person available in their own individual cyber discipline; but these separate expert individuals must gel into one single cohesive team. The best cake comes from using the best ingredients mixed and blended by the skill of the baker. The CISO must be that baker. “I use empowerment as my number one tool,” says Cardwell. “Instead of simply telling people what to do, I try to bring everyone together as a single body and ask, ‘What should we do? Let’s develop our strategy and plan how to get there, together.’ “I hate being told what to do,” she adds, “and I believe most people hate being told what to do. But I love being part of a mission, being part of a cause. So, the task is to get everyone to work together for that shared cause. The best way to achieve this is to define the cause together, to map out the route together, and achieve the shared destination together.” Rather than delegate a series of instructions, she empowers the team to find and achieve the tactics necessary for the right strategic outcome – one team rather than a collection of different experts. What type of person can achieve this goal of empowering others while still being the leader – what, in fact, is the primary and necessary character trait required to be a great CISO? “I’m torn between suggesting a deep sense of curiosity and a very low ego,” she says. “For me, they must both be present. You’re not going to be a great CISO if you’re not continuously trying to look deeper and deeper and deeper to find the root cause of a problem. But I also believe, if you feel you must behave as the smartest person in the room, you will drown everybody else’s ability to offer their own suggestions. Teams are only strong when every member of the team gets to be an operating part of that team. When there’s one person at the top, who’s the general and who’s always telling everyone what to do, the team will only be as smart as the general. So, I’m going to say low ego is the primary necessary trait for a CISO, because having a low ego also makes everyone better at curiosity.” CISO burnout While a leader must strive to get the best from the team, the CISO must also protect each member from the worst. In cybersecurity, that often means mental health. Working in cybersecurity is like living in a pressure cooker. The requirement is to let out excess steam before the pressure builds and breaks the cooker – and if it does break, that’s burnout. Burnout is both a tragedy for the person, and a danger to security. It is a chronic state of physical, emotional, and mental exhaustion resulting from prolonged and excessive stress. Tiredness can be ‘cured’ by a good night’s sleep. Burnout cannot. CISOs must constantly watch for any early sign of approaching burnout in their team members – but since ‘prolonged and excessive stress’ is almost part of the security job description, early prevention is better than waiting for the visible signs. “It’s a serious problem,” says Cardwell. “One of my approaches to handling this has been to introduce half day Fridays. No other department in the company has done this – but no other department gets a call at four in the morning saying get out of bed, we’ve got an emergency. It’s expected in security. Every person on the security team is basically on call 24 hours a day. If my expectation is that every individual will get out of bed or leave their dinner date or whatever it is – which I need them to do if we’re in the middle of an emergency – the least I can do is give back some amount of time that compensates for that time when we’re fighting a fire.” But for the team, it is more than just a few hours off – it is their CISO’s recognition that security professionals are firefighters subject to burnout. This feeling of being seen and cared for “really reduced the burnout across the team almost immediately and had a long lasting effect.” (This conversation was held on a Friday morning. Do you take your own advice? “I do. Actually, I plan to go to the beach this afternoon. But now that I’ve said that out loud, of course there’ll be an incident occur somewhere!”) Burnout is way beyond simple exhaustion. If it strikes hard, recovery is very difficult. Cardwell believes you need to catch it early to survive it effectively. “People don’t recognize that their mind is staying engaged with work for 50 hours and then 60 hours, until their spouse or their kids or their doctor says, ‘You got to stop. This is not healthy’. If that person can reach the early stage point and say, ‘Oh, I understand now. I don’t want to take another step. I’m exhausted. I don’t enjoy this…’ Only if they can recognize and remediate the acute stage before the chronic stage sets in can people recover from burnout – and not go there again.” Understanding a CISO We use four key indicators to help us understand how CISOs approach their role. These are their view on the biggest difficulty in being a CISO; the best career advice ever received (it’s likely to be foundational to how they operate); the advice they give to aspiring and promising team members (it shows what they think is important for the next generation of leaders based on their own experience); and their view on emerging threats. A CISO’s biggest difficulty. “It’s impossible to prove a negative. When a CISO is doing a great job, nobody notices, because nothing is happening, and it’s very difficult to look back and say, ‘Hey, we haven’t had an incident for the last five years – just look at what a great job I’m doing.’ The problem is you can’t tell whether you haven’t had an incident because you’re lucky or because you’re good. It’s easy to say we’ve had 2 billion attacks over the past five years, and we’ve managed to thwart them all. But that just leads to one of the hardest problems: it’s difficult to say I need more money, even though we haven’t had an incident.” Best career advice received. “The best career advice I ever received,” says Cardwell, “is to bring people along by giving credit – always give credit, never take credit. If I want to get somebody to do something and they do it, then they get all the credit for that, and I don’t take any of it. The next time I ask them to work with me, they’re going to be more likely and eager to do so because they know that I’m going to give them 100% of the credit for the work that they do.” Advice given. “Advice I frequently give is to understand we are not alone in this. If you’re not working with your peers, you are not doing it right. The first thing I do in a new CISO role is to reach out to the chief privacy officer and reach out to the head of audit, because it will make me stronger. If I drop a seed into the soil of the audit department and say, ‘Here’s something I see, but I can’t get any traction on it’, within a couple of months they’re going to start an audit on that place. I don’t have to be the person driving it anymore. I’ve essentially reached out to a partner, and now we’re teamed up on that problem.” Same with privacy. “In many respects, the privacy officer needs to do very similar work to what I’m trying to achieve. If I get closer to that person and partner with privacy, now we can pool our budgets and use the same tools to do the things we’re both trying to do, instead of coming at the problem from different angles.” Biggest current threat. “We’re beginning to see AI-generated spam emails that are so completely personalized to a CEO or a CFO that they look like part of an ongoing conversation – a conversation between the CEO and CFO, complete with thread, but all fake. Whole conversations and back stories written by AI and then brought over to accounting to pay a bill or an invoice. That level of precision and personalization doesn’t get caught by spam filters. It’s a whole different level of social engineering that I don’t think we’re prepared for, and I think it’s going to be one of the next big issues that we must handle.” Related: CISO Conversations: Maarten Van Horenbeeck, SVP & Chief Security Officer at Adobe Related: CISO Conversations: Jaya Baloo From Rapid7 and Jonathan Trull From Qualys Related: CISO Conversations: LinkedIn’s Geoff Belknap and Meta’s Guy Rosen Related: CISO Conversations: Nick McKenzie (Bugcrowd) and Chris Evans (HackerOne)
securityweek.comMar 11, 2026extracted
Bug bounties: The good, the bad, and the frankly ridiculous ways to do it
FEATURE Thirty years ago, Netscape kicked off the first commercial bug bounty program. Since then, companies large and small have bought into the idea, with mixed results. Bug bounties seem simple: a flaw finder spots a vulnerability, responsibly discloses it, and then gets a reward for their labor. But over the past decades, they've morphed into a variety of forms for commercial and government systems, using different payment techniques and platforms, and some setups are a lot more effective than others. Commercial bug bounties spread slowly at first, and the idea was initially fraught with danger for researchers. Some companies sued outsiders who found problems with their software. REG AD In 2005, Internet Security Systems (ISS) researcher Michael Lynn and the organizers of the Black Hat security conference in Las Vegas were served with a restraining order over his planned talk on serious flaws in Cisco's IOS router software. Lynn quit ISS and delivered the presentation anyway, while Cisco reps spent eight hours physically tearing pages describing the talk out of the conference handbook. REG AD But that same year, Tipping Point started the Zero Day Initiative, paying for high‑impact vulnerabilities with working proof‑of‑concepts. The practice went into turbo mode when several tech giants picked up the practice, led by Google in 2010, Facebook a year later, and then the biggie – Microsoft – in 2013. While some companies chose to run their own bounty programs, others outsourced it to platforms like HackerOne and Bugcrowd, both started in 2012. But the choice of which one to pick depends very much on the size and focus of your organization. Sorting it out in-house or outsourcing? For the biggest organizations with a large user base, the best option is to primarily run their own scheme. Katie Moussouris, who convinced Microsoft to go down the bug bounty route after a three-year fight (a process she described akin to "boiling a frog"), ran the Pentagon's first hacking competition, and was chief policy officer at HackerOne. She's now the CEO of Luta Security, a bug bounty consultancy. "If you are somebody like an Apple, Google, or Microsoft, where the sensitivity of your bugs is so high, you do not want [third-party] platforms triaging your bugs," she told us. "You also don't really want them housing the bugs at all. Any vulnerability in that third-party platform exposes your bugs." Larger organizations have a number of other advantages, she explained. Most bug bounty programs throw up a huge number of false positives or minor flaws that aren't really serious, and the biggest organizations, or those with a security bent, have the IT staff to sort out the wheat from the chaff. In addition, they have legal departments to handle the non-disclosure agreements that are an essential part of bug bounty programs. With Microsoft, she explained, the company originally set up a pilot called Project Tango (because it takes two to) where individual researchers would work for Redmond under an NDA not to release findings until Microsoft had checked them and issued a fix. REG AD In-house bug-bounty programs can also create a nice recruiting pipeline. "I used to run the one for Barracuda Networks," Eric Escobar, red team leader at Sophos Advisory Services, told us. "And in quality, 90 percent is trash, but the 10 percent that you got were like gold, it's incredible." He continued, "We hired several people out of the bug bounty program because they were finding such good stuff regularly. We did the cost analysis and thought if this person's finding this many bugs consistently per month, we're losing money if we don't hire them; they're making more than a solid AppSec engineer's salary would be for just finding bugs." But hiring dedicated bug finders isn't really an option for smaller software companies that don't have the budget. "It's very rare that you have an entirely research-focused security person, you want them doing other things," Moussouris said. "These people might not be programmers. They might not be able to tell the developers how to prevent those bugs in the future. They might just be really good at finding them." There's also a cultural issue, she said, since not everyone in the field wants to work in a corporate environment with endless meetings and team sessions. A lot of people like finding security holes but relish their independence. Increasingly, companies are hiring skilled pentesters on a per-contract basis for specific jobs. This solves the NDA issue, since non-disclosure would be part of the contract, the researcher gets money without having to make it a full-time career, and management is usually happy because they don't have to take on the financial overhead of a new staff member. The other alternative is to use a commercial platform like HackerOne or Bugcrowd. For smaller companies, or those less focused on security, this provides a way to get bugs in, screen them, and pay the finder's fee with minimal fuss, Moussouris said. REG AD HackerOne CEO Kara Sprague explains one big strength of the platform approach is the breadth of talent out there. "Going to a proven provider is not a bad idea for a company whose core competency is not offensive security," she told us. "The global independent researcher community is a phenomenal source of talent," she said, explaining that self-motivated bug finders are often more effective than in-house red teams or pentesters. In practice, many companies take a hybrid approach, running their own bug bounty programs internally but also using the platforms. Moussouris also warned that some companies were rushing into bug bounty programs for the wrong reasons – particularly public relations. Last month, when Paradox.ai was caught using "123456" as an admin password that would allow an attacker to access the personal details of about 64 million McDonald's job applicants, it apologized and promised to set up a bug bounty program. "I call that bug bounty botox, when they just want to be pretty on the outside," Moussouris joked. Motivation for hunters: Fortune, fame, and fixing things One common misconception is that flaw finders are just in it for the money, but it's more complicated than that. It's true that money is a factor. In the last decade, the amount of money up for grabs for bugs has exploded. At ZDI's forthcoming Pwn2Own contest, a lucky hacker can earn $1 million for a zero-click remote code execution attack on WhatsApp. And despite its initial reluctance Microsoft has become a firm supporter of the bounty system, and paid out $17 million last year to independent security researchers, Tom Gallagher, head of the Microsoft Security Response Center (MSRC), told The Register. A few vulnerability hunters have become millionaires from these platforms, and others have made a lot of money selling to third-party businesses who harvest high-value flaws to either exploit for government-sanctioned spyware or to sell premium detection services. The tactics to earn big bucks aren't what you might think, Moussouris opined. "The first hacker to make a million dollars total on HackerOne was asked 'did you just find a bunch of criticals? He's like, no, I don't look for criticals at all, they're too hard and take too long. I go for automation to get more efficient low- and medium-severity bugs.' The mediums are the sweet spot, because they pay more." But it's a long tail situation – most people don't make a massive amount of money, and the majority of bug hunters don't use it as a main source of income, Escobar explained. Microsoft's Gallagher explained that fame is another very effective way to attract bug hunters. MSRC maintains a league of the most useful flaw finders and competition is fierce, even if it's just for a t-shirt, which he kindly modeled for The Register. Companies also court top vulnerability researchers with access to in-house engineers and exclusive forums that are designed to woo the best talent into investigating their code. "One of the things that we try to do through the bounty program is we build a relationship with the researchers," he told us. "We try to build a community around it. We have a program where we call the most valuable researchers, and so we'll work with them. There are some people that are interested in working full time, there are other people that have a full time job. It may not even be security, and so it really depends on the individual." The other, often overlooked, motivation is the desire to get things fixed. A few security researchers still submit bug reports, not especially for the money, but to make sure that applications and processes are safe. "There are some researchers who care more about the bug being fixed than care about the payout, and that's still true," Moussouris opined. "Some researchers are like, 'No, I just want you to fix this bug,' that's their motivation." These unicorns are few and far between, however, and any company relying on the goodwill of such strangers as a primary source of fixes is foolish, she suggested. AI slopping over? As with many jobs in the tech industry, there's the spectre of machine learning and AI doing tasks previously reserved for humans. So far, AI is a mixed blessing. Yes, it's finding more flaws, faster, but on the other hand, machine-generated flaws and the reporting on them are flooding out bug analysis. As industry veteran Mikko Hyppönen pointed out at this year's Black Hat security shindig, there's been a huge increase in volume of reports, often written by script kiddies with prompt skills. "They call it AI slop," Moussouris commented. "It creates a lot of noise for maintainers, especially in the open source world, who can't afford the triage services. That's going to hurt all of us in the ecosystem long term." The bounty platforms are on the front lines of this trend, and HackerOne's Sprague says two-thirds of the reports they are getting these days "end up being valid vulnerabilities." To filter out the spam, the platform will be using AI moderation to examine reports and determine if they are valid exploits. But she said that software slipup seekers are gearing up as well, investing in automated scanning kit that will take a lot of the fingerwork out of scanning code. "We do see many of the bug hunters that I meet with have already adopted some amount of automation to facilitate their hunting," she said. "There's even other researchers that have developed their own hack bots, or are contributing to commercially developed bots. So we're seeing the researcher community increasingly invest in these sources of automation to scale their capacity." Will AI eclipse the human hacker? This hack doubts it. LLMs work on past information, and the intuitive leaps needed to spot serious problems appear to be beyond it, for now. ®
go.theregister.comAug 24, 2025extracted