logo

HackerOne Blog

ID: 5b0af042-2243-5e6a-92b9-087ace31a2ab

STIX ID: identity--5b0af042-2243-5e6a-92b9-087ace31a2ab

Feed Type: skeleton

Earliest post: 2017-12-11

Latest post: 2026-06-11

The HackerOne Blog covers the latest developments in cybersecurity, including AI security, vulnerability discovery, exposure management, offensive testing, and coordinated disclosure.

01/01/2020
06/13/2026
Title Date Published Describes IncidentAuthorVisible
Closing the Exposure Gap: What pixiv Learned About Continuous Security Testing2026-06-10TrueTrue
Continuous Threat Exposure Management and the Remediation Crisis2026-06-10TrueTrue
AI Vulnerability Discovery Is Outpacing Remediation2026-06-10TrueTrue
Vulnerability Exploitability: GPT-5.5 vs Claude Benchmarks2026-05-10TrueTrue
Continuous Security Validation in Practice: XSS Workflow Case Study2026-04-14TrueTrue
How to Find XSS Vulnerabilities: Practical Security Guide2026-04-07TrueTrue
Roni Carta: From Bug Bounties to Building a Safer Supply Chain2026-01-29TrueTrue
The Top Researcher Signals From HackerOne’s 2025 HPSR2026-01-06TrueTrue
CVE-2025-55182: Critical React Exploit Hits Millions of Sites2025-12-06TrueTrue
Shai-Hulud 2.0: Responding to the npm Worm Threatening CI/CD Security2025-11-26TrueTrue
HackerOne Incident Update: Salesforce2025-11-10TrueTrue
AI Security Findings Outpace Cybersecurity Remediation in 20252025-10-27TrueTrue
AI Security Risks and Vulnerabilities Enterprises Must Address2025-09-30TrueTrue
GCP Security Configuration Review and Best Practices2025-08-12TrueTrue
Pentesting your external network with HackerOne2025-08-06TrueTrue
Pentesting for APIs and Best Practices2025-08-04TrueTrue
Pentesting for Web Applications2025-07-31TrueTrue
AWS Security Configuration Review and Best Practices2025-07-30TrueTrue
CVE-2025-53770: What Security Teams Need to Know About the SharePoint RCE Vulnerability2025-07-23TrueTrue
Pentesting for iOS Mobile Applications2025-07-08TrueTrue
How a GraphQL Bug Resulted in Authentication Bypass2025-07-08TrueTrue
A Guide To Subdomain Takeovers 2.02025-07-08TrueTrue
Pentesting for AI and Large Language Models2025-07-08TrueTrue
Securing Our Elections Through Vulnerability Testing and Disclosure2025-06-27TrueTrue
Testing Hai Insight Agent in Our Bug Bounty Program2025-06-24TrueTrue
10 Steps to Avoid Social Engineering Attacks2025-05-21TrueTrue
Smart Contracts: Common Vulnerabilities and Real-World Cases2025-05-13TrueTrue
Pentesting for Android Mobile Applications2025-05-07TrueTrue
Lessons from Crypto Exploits2025-03-10TrueTrue
Join HackerOne’s Ambassador World Cup2025-02-19TrueTrue
The OWASP Top 10 for LLMs 2025: How GenAI Risks Are Evolving2024-12-18TrueTrue
Azure Cloud Configuration Review2024-12-13TrueTrue
How a Privilege Escalation Led to Unrestricted Admin Account Creation in Shopify2024-12-12TrueTrue
How HackerOne Disproved an MFA Bypass With a Spot Check2024-11-27TrueTrue
How an Improper Access Control Vulnerability Led to Account Theft in One Click2024-11-27TrueTrue
How an Information Disclosure Vulnerability Led to Critical Data Exposure2024-11-27TrueTrue
How a Cross-Site Scripting Vulnerability Led to Account Takeover2024-11-27TrueTrue
How a Business Logic Vulnerability Led to Unlimited Discount Redemption2024-11-27TrueTrue
Vulnerability Deep Dive: Gaining RCE Through ImageMagick With Frans Rosen2024-11-27TrueTrue
Pentesting for Internal Networks2024-11-27TrueTrue
How an IDOR Vulnerability Led to User Profile Modification2024-11-27TrueTrue
Common Ecommerce Vulnerabilities: Reflected XSS2024-11-27TrueTrue
How Ethical Hackers Are Securing Elections2024-11-27TrueTrue
How Serialized Cookies Led to RCE on a WordPress Website2024-11-26TrueTrue
How a Prompt Injection Vulnerability Led to Data Exfiltration2024-11-26TrueTrue
How a Race Condition Vulnerability Could Cast Multiple Votes2024-11-26TrueTrue
XZ Utils CVE-2024-3094: A Tale of Broken Trust, Curious Persistence, and a Call to Action2024-11-26TrueTrue
AI Safety vs. AI Security2024-11-26TrueTrue
Meet HackerOne’s Brand Ambassadors That Break the Hacker Stereotype2024-11-26TrueTrue
(Best) Practice Makes Perfect2024-11-26TrueTrue

1–50 of 112