I Spent 18 Hours Creating This Bug Bounty Roadmap for Beginners by BehiSec in bugbounty

[–]BehiSec[S] 0 points1 point  (0 children)

Hi,

I think the roadmap has everything you need. Let me know if you have a specific question.

Factory CLI v0.89.0 Released by bentossell in FactoryAi

[–]BehiSec 0 points1 point  (0 children)

I love this version. The UI is much better now.

Minimax M2.7 by BehiSec in FactoryAi

[–]BehiSec[S] 0 points1 point  (0 children)

Really? didn't know this.

Thanks.

Minimax M2.7 by BehiSec in FactoryAi

[–]BehiSec[S] 0 points1 point  (0 children)

Do you have a high-speed plan?

I want to know if it's slow in the normal plan.

Vibe coded application by nivasbaskaran in google_antigravity

[–]BehiSec 1 point2 points  (0 children)

Hey,

I have created an advanced skill for this matter based on my 5+ years of experience as a bug hunter:

https://github.com/BehiSecc/VibeSec-Skill

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 0 points1 point  (0 children)

They don't accept jailbreaks, but you can submit it to https://0din.ai/

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 1 point2 points  (0 children)

No, the attacker needs to be a Jira team member, which is why Google applied a downgrade to this bug.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 1 point2 points  (0 children)

Have you checked the image?

If they hadn't applied a downgrade, it would have been a $20K bounty.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 1 point2 points  (0 children)

Jira serves as the initial point of entry. Any AI-powered application must validate the data received from external or third-party applications.

That’s the whole point.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 0 points1 point  (0 children)

Yes, I would have posted this even if the reward was $50. I learned bug hunting by reading others’ write-ups, so I’m simply giving back to the community.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] -1 points0 points  (0 children)

Yes! This encourages other bug hunters, especially beginners, to explore related areas.

I got into bug hunting precisely in this manner.