Skip to content

company

HackerOne

HackerOne is a vulnerability coordination and bug bounty platform that connects organizations with security researchers to find and report security flaws.

Current stories

build1 publisher

Cantina's open-weights exploit model ran a 60-task security eval for $2.38

Cantina released apex-flash-1, an open-weights vulnerability-research model it says solved 40 of 60 tasks for $2.38, against $74.68 for Claude Opus 5 High. There is no hosted endpoint, so teams download the 321-billion-parameter weights, pay for their own inference and verify the numbers themselves.

Publishers:runtimewire.com

Reality

Evidence45
Adoption
Insufficient
Hype gap+35
Incentives70
Confidence40
security4 publishers

GitLab patches sandbox escape that lets Duo agent users run commands on self-hosted AI Gateways

GitLab patched CVE-2026-90970, a sandbox escape that lets any authenticated Duo Agent Platform user run arbitrary commands on a self-hosted AI Gateway. Customers on GitLab's hosted gateway are already protected, so the upgrade falls to Self-Managed shops that run their own.

Perspective Coverage

4 publishers
Builder
Builder 24%
Operator
Operator 59%
Investor
Investor 17%

Reality

Evidence78
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence74
security3 publishers

Cloudflare Containers handed new tenants disk blocks still holding other customers' data

Cloudflare fixed a Containers flaw that let paying customers read other tenants' leftover disk data, found on 18 of 24 production tries. Sandboxes, the product it sells for running untrusted and AI-written code, was affected too.

Perspective Coverage

3 publishers
Builder
Builder 42%
Operator
Operator 48%
Investor
Investor 10%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives55
Confidence70
security3 publishers

Public READMEs are leaking GitLab email tokens that let any sender act as the account owner

Aikido found a dozen live GitLab 'email work item' addresses in public docs, each carrying a long-lived token that lets any mailbox act as its owner. GitLab calls it intended behavior, so maintainers must pull the address and reset the token.

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 52%
Investor
Investor 5%

Reality

Evidence68
Adoption28
Hype gap+10
Incentives52
Confidence60
security4 publishers

A Copilot Autofix Wrote the Bug, and an Autonomous Agent Cashed It for Snowflake's Jira

Wiz says its Red Agent found and exploited a GitHub Actions injection that an AI "autofix" commit introduced five days earlier, reaching Snowflake's internal Jira with no human in the loop.

Perspective Coverage

4 publishers
Builder
Builder 43%
Operator
Operator 42%
Investor
Investor 15%

Reality

Evidence58
Adoption
Insufficient
Hype gap+35
Incentives70
Confidence62
security7 publishers

GitLab's 9.4 GraphQL bug went from patch to in-the-wild traffic in about two days

WatchTowr reproduced CVE-2026-19478 from the advisory and patch alone, then caught the first exploitation attempts on its honeypots. Self-managed owners do not get a week to schedule this.

Perspective Coverage

7 publishers
Builder
Builder 29%
Operator
Operator 62%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+20
Incentives65
Confidence70
security6 publishers

Encrypted prompts walk past Grok and Gemini guardrails, and no one owns the bug

Adversa AI says its Cryptographic Context Injection recovers hostile prompts inside the code sandbox, where filters do not look. xAI has not replied; Google scopes jailbreaks out entirely.

Perspective Coverage

6 publishers
Builder
Builder 34%
Operator
Operator 55%
Investor
Investor 11%

Reality

Evidence50
Adoption
Insufficient
Hype gap+30
Incentives55
Confidence55
security4 publishers

OpenAI gives water utilities and community banks six months to spend $1 billion in Daybreak credit

The billion is credit against OpenAI's own products rather than cash, aimed at water, grid, local government and open-source defenders, and OpenAI wants it consumed within six months, which turns model-assisted triage into a procurement question.

Perspective Coverage

4 publishers
Builder
Builder 24%
Operator
Operator 54%
Investor
Investor 22%

Reality

Evidence55
Adoption30
Hype gap+30
Incentives70
Confidence60
science4 publishers

Security researchers answer a 10 percent extinction estimate by counting tool calls

An Anthropic alignment lead put the chance of AI killing all humans within a decade above 10 percent. The four containment failures his company has disclosed are countable. Security practitioners say those are the numbers to work from.

Publishers:interconnects.ainewscientist.comphys.orgscientificamerican.com

Perspective Coverage

4 publishers
Builder
Builder 35%
Operator
Operator 41%
Investor
Investor 24%

Reality

Evidence55
Adoption
Insufficient
Hype gap+40
Incentives60
Confidence55

Earlier coverage

  1. An encrypted payload turns Grok's own navigation tool into the exfiltration path

    Build · September 10, 2026 · 1 publisher

  2. cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root

    Security · September 9, 2026 · 1 publisher

  3. IMDSv1 turns an SSRF finding into unauthenticated credential theft in one hop

    Build · September 6, 2026 · 1 publisher

  4. Recorded Future's half-year data shows adversaries continuing to favor abusing legitimate tools and trusted platforms already inside the enterprise

    Security · September 3, 2026 · 1 publisher

  5. Three AI scanners disagreed on 95 percent of one codebase's findings in Contrast's test

    Security · August 31, 2026 · 1 publisher

  6. Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name

    Product · August 27, 2026 · 1 publisher

  7. GitLab ships five security fixes and keeps the details sealed until October

    Build · August 23, 2026 · 1 publisher

  8. Grok still hands over whole chat histories 11 weeks after disclosure, Adversa says

    Invest · August 20, 2026 · 1 publisher

  9. Cursor runs a repository's own git.exe on Windows, and has done for months

    Science · August 19, 2026 · 1 publisher

  10. The disclosure pipeline is triaging itself: 20,700 new CVEs, 10% more exploitation

    Security · August 19, 2026 · 1 publisher

  11. The AI-wrote-it claim died in eight hours. The Actions injection pattern did not.

    Product · August 17, 2026 · 1 publisher