buildOne report1 publisher Hacktron chained a heap overflow in libheif to an OpenAI SSO flaw and opened a pull request in OpenAI's internal monorepo in under 72 hours. The bug had been fixed upstream a year earlier, but the fix never reached Debian's packages.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives50
- Confidence40
buildConfirmed14 publishers Google stopped taking product vulnerability reports for its open-source bug bounty on October 1 after a flood of invalid AI-generated submissions. Any team that takes outside security reports faces the same imbalance, with reports now cheap to write and as costly as ever to check.
Perspective Coverage
15 publishers
- Builder
- Builder 41%
- Operator
- Operator 50%
- Investor
- Investor 9%
Reality
- Evidence76
- Adoption55
- Hype gap+20
- Incentives35
- Confidence72
The libheif bug was fixed upstream a year earlier without a security label or a CVE, so a Discourse image check that ignored HEIC left it reachable, and forum sign-in tokens carried full API access to the accounts behind them.
Perspective Coverage
6 publishers
- Builder
- Builder 35%
- Operator
- Operator 55%
- Investor
- Investor 10%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence66
HackerOne says companies cut average vulnerability fix time from 135 days to 62, yet validated findings left unresolved rose 131% over two years. That leaves time-to-fix a poor guide to exposure, and paying the debt down means taking capacity away from feature work.
Reality
- Evidence45
- Adoption50
- Hype gap+25
- Incentives70
- Confidence45
Meta began fixing KVM escapes in its Muse AI agent on August 27, 11 days before launch, an internal post seen by 404 Media shows. Each agent's VM holds its owner's email and account access, so a break-out would reach other users and Meta's own systems.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence58
buildOne report1 publisher Patrick Wardle found that any local process on a Mac can redirect Meta Muse's voice endpoint and capture its account token, with no macOS permission needed. Muse also zipped and exported the 6.8 GB root filesystem of its own sandbox on request.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence40
Faav, a 16-year-old researcher, reached admin SQL over 17.3 trillion rows on Microsoft's Titan service because it never checked login-token signatures. Microsoft locked the endpoint four days after his report and paid a $5,000 bounty.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+35
- Incentives55
- Confidence55
buildConfirmed2 publishers Faav, 16, impersonated an administrator on Microsoft's internal Titan service with an unsigned token, reaching an estimated 17.3 trillion rows. Microsoft disabled the API four days after his report and paid a $5,000 bounty.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+30
- Incentives55
- Confidence55
buildOne report1 publisher Meta is adding a clearer warning to Muse, downloaded about 2.8 million times, after a flaw could have opened a user's cloud VM to an attacker. That VM holds the user's email and files, and the warning is the only response the reports describe.
Publishers:ksl.com · malaysia.news.yahoo.com
Reality
- Evidence35
- Adoption50
- Hype gap0
- Incentives
- Insufficient
- Confidence45
buildConfirmed2 publishers Meta's Muse agent wrote 6.8GB of its own Linux environment, SSH key files included, to Mouse founder Peter James's Google Drive, he says. James has not tested the keys, yet the export shows anything baked into an agent's image can leave through a storage connector the user linked.
Publishers:t.signalplus.com · tokenpost.com
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives
- Insufficient
- Confidence40
CrowdStrike says the npm stealer's author has been active since November 2022, claims bounties from at least nine companies, and that none of the stolen logs have turned up for sale. It assesses with high confidence that an LLM wrote the code.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence58
The image parsing bug had been fixed upstream about a year earlier, and the decision not to ship that fix belonged to Discourse. OpenAI's forum shared single sign-on with internal systems, so a forum account became GitHub access.
Perspective Coverage
9 publishers
- Builder
- Builder 35%
- Operator
- Operator 39%
- Investor
- Investor 26%
Reality
- Evidence70
- Adoption63
- Hype gap+28
- Incentives60
- Confidence62
Gal Weizman showed that one malicious extension can take over the AI agents in Chrome, Comet, Edge, Neon and Claude in Chrome, with bounties from all five vendors to show for it. Installation is the only precondition.
Perspective Coverage
3 publishers
- Builder
- Builder 54%
- Operator
- Operator 38%
- Investor
- Investor 8%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+30
- Incentives62
- Confidence64
buildOne report1 publisher An open-source gateway author walked Hacktron's five-step path into OpenAI through his own seven detection layers. The first two hops are requests to a forum and an identity provider. Where the gateway is deployed decides what any of it can read.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+60
- Incentives80
- Confidence45
Private Processing runs glasses workloads in confidential VMs and logs every production image in an append-only public ledger, so the isolation claim can be checked from outside, though the matching binaries reach researchers only under agreement.
Reality
- Evidence44
- Adoption28
- Hype gap+24
- Incentives66
- Confidence58
buildOne report1 publisher The program paid for critical vulnerabilities for about a year and closed because generating a plausible report now costs about a tenth of a cent while reading one still costs ten minutes of the person who knows the code.
Reality
- Evidence40
- Adoption25
- Hype gap+20
- Incentives30
- Confidence45
Meta's bug bounty puts $130,000 on a prompt injection against Muse out of a $300,000 top payout. A researcher has now demonstrated a working hijack of the agent Meta sells as safe enough to complete purchases.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+38
- Incentives68
- Confidence34
buildOne report1 publisher Hacktron's path into OpenAI's internal repos ran through a libheif bug Debian had not backported and a single sign-on flow that trusted community.openai.com. The dev.to breakdown says the model changed what the attack cost. The category of attack was the same either way.
Reality
- Evidence66
- Adoption72
- Hype gap−12
- Incentives58
- Confidence63
buildOne report1 publisher The strict-dynamic directive passes a script's trust to everything that script loads, and Ryan Chaplin of Raxis used that rule to get an XSS payload executing under a nonce-based policy that had blocked it.
Reality
- Evidence55
- Adoption30
- Hype gap+22
- Incentives62
- Confidence50
buildOne report1 publisher The case that generated code fails without the usual warning signs comes from two practitioner accounts, while the only measured series is curl's inbound bug reports, and Daniel Stenberg stopped taking those in January 2026.
Reality
- Evidence38
- Adoption58
- Hype gap+34
- Incentives62
- Confidence46