<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>bug bounty &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/bug-bounty/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Thu, 22 May 2025 13:00:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Resolving a request smuggling vulnerability in Pingora</title>
		<link>https://noise.getoto.net/2025/05/22/resolving-a-request-smuggling-vulnerability-in-pingora/</link>
		
		<dc:creator><![CDATA[Edward Wang]]></dc:creator>
		<pubDate>Thu, 22 May 2025 13:00:00 +0000</pubDate>
				<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[CDN]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[Pingora]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ecccd1e717579e10bf69659cc2f94d7f</guid>

					<description><![CDATA[Cloudflare patched a vulnerability (CVE-2025-4366) in the Pingora OSS framework, which exposed users of the framework and Cloudflare CDN’s free tier to potential request smuggling attacks.]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>QUIC action: patching a broadcast address amplification vulnerability</title>
		<link>https://noise.getoto.net/2025/02/10/quic-action-patching-a-broadcast-address-amplification-vulnerability/</link>
		
		<dc:creator><![CDATA[Josephine Chow]]></dc:creator>
		<pubDate>Mon, 10 Feb 2025 14:00:00 +0000</pubDate>
				<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[Edge]]></category>
		<category><![CDATA[HTTP3]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=27713c01d9baafebc1f53cf45f3582db</guid>

					<description><![CDATA[Cloudflare was recently contacted by researchers who discovered a broadcast amplification vulnerability through their QUIC Internet measurement research. We've implemented a mitigation.]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Advancing cybersecurity: Cloudflare implements a new bug bounty VIP program as part of CISA Pledge commitment</title>
		<link>https://noise.getoto.net/2024/09/27/advancing-cybersecurity-cloudflare-implements-a-new-bug-bounty-vip-program-as-part-of-cisa-pledge-commitment/</link>
		
		<dc:creator><![CDATA[Sri Pulla]]></dc:creator>
		<pubDate>Fri, 27 Sep 2024 13:00:00 +0000</pubDate>
				<category><![CDATA[Birthday Week]]></category>
		<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=fee7eda56f01e661775da4be54facfdd</guid>

					<description><![CDATA[Cloudflare strengthens its commitment to cybersecurity by joining CISA's "Secure by Design" pledge. In line with this commitment, we're enhancing our vulnerability disclosure policy by launching a VIP bug bounty program, giving top researchers early access to our products. Keep an eye out for future updates regarding Cloudflare's CISA pledge as we work together to shape a safer digital future.]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Mitigating a token-length side-channel attack in our AI products</title>
		<link>https://noise.getoto.net/2024/03/14/mitigating-a-token-length-side-channel-attack-in-our-ai-products/</link>
		
		<dc:creator><![CDATA[Celso Martinho]]></dc:creator>
		<pubDate>Thu, 14 Mar 2024 12:30:30 +0000</pubDate>
				<category><![CDATA[AI Gateway]]></category>
		<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[Developer Platform]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[SASE]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Workers AI]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3366a425c9b65e56319b236f0d06198f</guid>

					<description><![CDATA[The Workers AI and AI Gateway team recently collaborated closely with security researchers at Ben Gurion University regarding a report submitted through our Public Bug Bounty program. Through this process, we discovered and fully patched a vulnerability affecting all LLM providers. Here’s the story]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Championing CyberSecurity: Grab&#8217;s bug bounty programme in 2023</title>
		<link>https://noise.getoto.net/2023/12/19/championing-cybersecurity-grabs-bug-bounty-programme-in-2023/</link>
		
		<dc:creator><![CDATA[Grab Tech]]></dc:creator>
		<pubDate>Tue, 19 Dec 2023 00:00:10 +0000</pubDate>
				<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[Engineering]]></category>
		<category><![CDATA[HackerOne]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://engineering.grab.com/cybersec-bug</guid>

					<description><![CDATA[Launched in 2015, Grab’s Security bug bounty programme has achieved remarkable success and forged strong partnerships within a thriving bounty community. By holding quarterly campaigns with HackerOne, Grab has been dedicated to security and giving back...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Cloudflare&#8217;s handling of a bug in interpreting IPv4-mapped IPv6 addresses</title>
		<link>https://noise.getoto.net/2023/02/02/cloudflares-handling-of-a-bug-in-interpreting-ipv4-mapped-ipv6-addresses/</link>
		
		<dc:creator><![CDATA[Lucas Ferreira]]></dc:creator>
		<pubDate>Thu, 02 Feb 2023 13:32:00 +0000</pubDate>
				<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ed6e598c531c2b477f48314aa78e96d2</guid>

					<description><![CDATA[Recently, a vulnerability was reported to our bug bounty about a bug in the way some of our code interprets IPv4 addresses mapped into IPv6 addresses. Read about how Cloudflare addressed this vulnerability and what will prevent similar exploits in the future.]]></description>
		
		
		<enclosure url="http://blog.cloudflare.com/content/images/2023/02/image1.png" length="0" type="" />

			</item>
		<item>
		<title>The Cloudflare Bug Bounty program and Cloudflare Pages</title>
		<link>https://noise.getoto.net/2022/05/06/the-cloudflare-bug-bounty-program-and-cloudflare-pages/</link>
		
		<dc:creator><![CDATA[Evan Johnson]]></dc:creator>
		<pubDate>Fri, 06 May 2022 13:56:56 +0000</pubDate>
				<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=8521dc6679053da564b4c5f08f252657</guid>

					<description><![CDATA[The Cloudflare Bug Bounty has resulted in numerous security improvements to Cloudflare Pages]]></description>
		
		
		<enclosure url="http://blog.cloudflare.com/content/images/2022/05/image6-2.png" length="0" type="" />

			</item>
		<item>
		<title>Cloudflare&#8217;s Handling of an RCE Vulnerability in cdnjs</title>
		<link>https://noise.getoto.net/2021/07/24/cloudflares-handling-of-an-rce-vulnerability-in-cdnjs/</link>
		
		<dc:creator><![CDATA[Jonathan Ganz]]></dc:creator>
		<pubDate>Sat, 24 Jul 2021 12:57:57 +0000</pubDate>
				<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[CDNJS]]></category>
		<category><![CDATA[Path Traversal]]></category>
		<category><![CDATA[RCE]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=9054c78aa548a0b876f9daebf8c71983</guid>

					<description><![CDATA[Recently, a RCE vulnerability in the way cdnjs’ backend is automatically keeping web resources up to date has been disclosed. Read about how Cloudflare handled the security incident and what will prevent similar exploits in the future.]]></description>
		
		
		<enclosure url="https://blog.cloudflare.com/content/images/2021/07/cdnjs-OG.png" length="0" type="" />

			</item>
		<item>
		<title>Reflecting on the five years of Bug Bounty at Grab</title>
		<link>https://noise.getoto.net/2020/12/16/reflecting-on-the-five-years-of-bug-bounty-at-grab/</link>
		
		<dc:creator><![CDATA[Grab Tech]]></dc:creator>
		<pubDate>Wed, 16 Dec 2020 00:00:00 +0000</pubDate>
				<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[HackerOne]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://engineering.grab.com/reflecting-on-the-five-years-of-bug-bounty-at-grab</guid>

					<description><![CDATA[Security has always been a top-priority at Grab; our product security team works round-the-clock to ensure that our customers’ data remains safe. Five years ago, we launched our private bug bounty program on HackerOne, which evolved into a public progr...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 31/214 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-11 04:46:39 by W3 Total Cache
-->