Beyond CVSS: rethinking scoring systems amidst AI Safety and Security
CVSS no fue diseñado para bugs de sistemas de IA. El artículo discute por qué la escala se rompe y qué alternativas hay sobre la mesa.
Curated archive · Bug bounty
A timeline of bug bounty writeups and research. Every entry is verified against its source and classified by bug type — so you can filter instead of scroll.
Latest
CVSS no fue diseñado para bugs de sistemas de IA. El artículo discute por qué la escala se rompe y qué alternativas hay sobre la mesa.
CSS sanitizado en clientes de webmail resulta suficiente para exfiltrar tokens con attribute selectors, spoofear UI y montar un keylogger sin una línea de JavaScript. Afecta a Gmail, Outlook, Fastmail y ProtonMail.
Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how organizations build and ship products, security testing needs to keep pace. Intigriti's global community of
How it works
Each writeup is a file in data/writeups/. No database, no admin panel. The change history is the git history.
Add a file, open a pull request, and CI validates the schema. If it passes, it lands in the archive with your name on the commit.
A GitHub Action checks the feeds daily and posts what's new to Discord. The site is the archive; the bot is the notification.