HackerOne 'ghosted' me for months over $8,500 bug bounty, says researcher
ID: 019efc45-aa21-5e7e-a796-6220d6ccc717
STIX ID: report--019efc45-aa21-5e7e-a796-6220d6ccc717
Feed Name: The Register (Security)
Threat Score
Last fall, researcher Jakub Ciolek reported two high-severity unauthenticated denial-of-service vulnerabilities in Argo CD (CVE-2025-59538 and CVE-2025-59531) that were patched and credited to him; however, HackerOne's Internet Bug Bounty program allegedly failed to communicate and delayed his reward payment, raising concerns about program responsiveness and trust. The report notes fixes were released and provides no evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
