ζεΏ / Antiquarian @ IBM Adversary Services / Ex-TORE βοΈπ¦ / I rewrite pointers and read memory / AI Psychoanalyst / Teaching @CalypsoLabs
Aug 13, 2021 β’ 5 tweets β’ 3 min read
Let's have a #RealTalk moment. In recent years there has been a degeneration of the software bounty industry. Focussing on MSFT here (but it's not exclusive to their program). We had a lot of, "not a boundary", "that thing is not in scope", nerfing the payouts into the ground 1/n
, one of my favourites, "this app has live updates so we don't assign CVE's" and finally on-prem critical infra like Exchange and Sharepoint aren't eligible at all (lol wut, come again?)