Bug bounties in the Mythos era
ID: 2c877ad5-273e-5117-a584-9d89ff33d66b
STIX ID: report--2c877ad5-273e-5117-a584-9d89ff33d66b
Feed Name: Sophos Blogs
This report explains how AI is reshaping bug bounty programs—producing both a surge of low-signal automated submissions and rapidly improving capabilities that can surface validated, high-severity vulnerabilities—summarizes Sophos’s 2025 bounty metrics and program changes, and recounts past incidents (Asnarök, Personal Panda) where zero-days were exploited and suspicious bounty submissions appeared, arguing for stronger evidence requirements, automated validation, and program guardrails in the ‘Mythos’ era.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
