organization · 3 records
HackerOne

Malicious npm Package Poses as Twilio Bug-Bounty Probe
Researchers discovered a malicious npm package that mimics a Twilio security tool to steal developer credentials and environment data.
1 outlet

Amazon Kiro IDE security vulnerability allows remote command execution
CVE-2026-10591 disclosed: Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions
2 outlets Markets read Cyber read

GitHub reduces public bug bounty payouts and introduces new VIP reward tier
GitHub cuts public bug bounty payouts by half starting July 27, 2026, while increasing rewards for a VIP tier and citing AI-generated report noise as a driver for the policy change.
1 outlet