Vulnerability Research
4 articles RSS
Microsoft Expands Bug Bounty Program to Open Source and Third-Party Code, Pays Record $20 Million
Microsoft's bounty program paid over $20 million to 562 researchers this year after expanding scope to cover open-source software and third-party components.
3 min read3 sources
Forescout Finds 15 Vulnerabilities in TP-Link's Omada Zero-Touch Provisioning System, Chainable Into Full Network Takeover
Vedere Labs disclosed 15 flaws in TP-Link Omada's zero-touch provisioning system at Black Hat USA, some chainable into root-level network compromise.
5 min read3 sources
GitHub Cuts Public Bug Bounty Payouts by Half, Moves Top Rewards Behind a New Invite-Only VIP Tier
GitHub is halving public bug bounty payouts starting July 27, reserving its largest rewards for a new invite-only VIP tier as it fights a flood of low-quality, AI-generated reports.
4 min read4 sources
Pwn2Own Berlin 2026 Closes With $1.3 Million in Prizes and 47 Zero-Days as DEVCORE Claims Master of Pwn
DEVCORE took the top prize with $505,000 and 50.5 points after three days at OffensiveCon, where 47 unique zero-days in Windows, Exchange, VMware, and AI tools earned researchers $1,298,250.
4 min read6 sources