{
  "schema_version": "1.2.0",
  "dataset": "security-research-library",
  "as_of": "2026-10-03",
  "latest_reviewed_at": "2026-10-04T23:34:10Z",
  "purpose": "Historical public-disclosure research and defensive skill development for authorized reviews",
  "inclusion_policy": {
    "minimum_individual_award": 10000,
    "currency": "USD",
    "preferred_publication_window_months": 12,
    "counts_award_announcements": true,
    "independent_cash_settlement_audit": false,
    "program_maximums_and_aggregate_earnings_excluded": true,
    "competition_awards_explicitly_labeled": true,
    "payloads_and_reproduction_steps_excluded": true
  },
  "counts": {
    "included": 67,
    "within_preferred_window": 25,
    "older_or_uncertain": 42,
    "bug_bounty": 56,
    "competition_award": 11
  },
  "downstream_compatibility": "Portable research export only. A vulns.co ingestion contract has not been supplied or validated; no ingestion or deployment is performed.",
  "taxonomy": {
    "schema_version": "1.0.0",
    "categories": [
      {
        "id": "authorization",
        "title": "Authorization and tenant boundaries",
        "description": "Object, role, account, and tenant access-control design"
      },
      {
        "id": "authentication",
        "title": "Authentication and identity",
        "description": "Account lifecycle, session integrity, identity-provider trust"
      },
      {
        "id": "business-logic",
        "title": "Business logic and concurrency",
        "description": "State transitions, approval integrity, and transactional invariants"
      },
      {
        "id": "cloud-security",
        "title": "Cloud permissions and isolation",
        "description": "Service identities, IAM boundaries, tenant isolation, and delegated authority"
      },
      {
        "id": "supply-chain",
        "title": "Software supply-chain security",
        "description": "Build systems, package provenance, release integrity, and automation trust"
      },
      {
        "id": "injection",
        "title": "Injection and untrusted input",
        "description": "Separation between untrusted data and executable interpretation"
      },
      {
        "id": "ai-security",
        "title": "AI integration boundaries",
        "description": "Authority boundaries around model input, tools, and downstream actions"
      },
      {
        "id": "client-security",
        "title": "Client and browser security",
        "description": "Client-side isolation, memory safety, and security-sensitive state"
      },
      {
        "id": "server-request-trust",
        "title": "Server-side request trust",
        "description": "Destination validation and boundaries in server-initiated requests"
      },
      {
        "id": "memory-safety",
        "title": "Memory safety and parser contracts",
        "description": "Safe length, lifetime, encoding, and component-boundary assumptions"
      },
      {
        "id": "information-exposure",
        "title": "Information exposure and response privacy",
        "description": "Unintended disclosure through error responses, diagnostics and output contracts"
      }
    ],
    "skillsets": [
      {
        "id": "authorization-modeling",
        "title": "Model access-control invariants",
        "defensive_objective": "Document expected actor, action, resource, and tenant relationships in an authorized design review"
      },
      {
        "id": "identity-lifecycle-review",
        "title": "Review identity lifecycle",
        "defensive_objective": "Assess binding, verification, recovery, linking, and revocation requirements using approved test accounts"
      },
      {
        "id": "approval-state-integrity",
        "title": "Review approval-state integrity",
        "defensive_objective": "Check that approval records bind to immutable content and survive state changes safely"
      },
      {
        "id": "concurrency-reasoning",
        "title": "Reason about concurrent state",
        "defensive_objective": "Model ordering assumptions and prove security invariants with local state-machine or unit tests"
      },
      {
        "id": "cloud-iam-review",
        "title": "Review cloud IAM boundaries",
        "defensive_objective": "Compare intended service authority with documented effective permissions and least-privilege requirements"
      },
      {
        "id": "integration-threat-modeling",
        "title": "Threat-model integrations",
        "defensive_objective": "Trace documented trust assumptions between services and identify where authorization responsibility changes"
      },
      {
        "id": "pipeline-trust-modeling",
        "title": "Model build and release trust",
        "defensive_objective": "Map trusted and untrusted inputs, artifacts, jobs, and identity boundaries in approved architecture diagrams"
      },
      {
        "id": "cache-artifact-isolation",
        "title": "Review artifact isolation",
        "defensive_objective": "Assess separation of caches and artifacts by trust level, and define integrity controls"
      },
      {
        "id": "dependency-provenance",
        "title": "Review dependency provenance",
        "defensive_objective": "Check explicit registries, namespace ownership, lockfiles, source pinning, and package-origin policy"
      },
      {
        "id": "machine-identity-governance",
        "title": "Review machine identities",
        "defensive_objective": "Document bot and service identity privileges, rotation, approvals, and separation of duties"
      },
      {
        "id": "secrets-containment",
        "title": "Review secrets containment",
        "defensive_objective": "Assess whether secrets are limited to the minimum necessary trusted execution contexts"
      },
      {
        "id": "untrusted-input-handling",
        "title": "Review input trust boundaries",
        "defensive_objective": "Assess validation and data/code separation without collecting offensive payloads"
      },
      {
        "id": "ai-authority-boundaries",
        "title": "Review AI authority boundaries",
        "defensive_objective": "Assess least privilege and independent validation at tool execution and data disclosure boundaries"
      },
      {
        "id": "secure-parser-review",
        "title": "Review parsing and serialization",
        "defensive_objective": "Reason about parser consistency, validation, and safe serialization contracts"
      },
      {
        "id": "browser-isolation-review",
        "title": "Review client isolation",
        "defensive_objective": "Study process, origin, memory-safety, and permission boundaries in patched historical cases"
      },
      {
        "id": "defensive-evidence-writing",
        "title": "Write bounded security evidence",
        "defensive_objective": "Separate demonstrated impact, modeled impact, remediation, and source uncertainty in review findings"
      },
      {
        "id": "encoding-invariant-review",
        "title": "Review text-encoding invariants",
        "defensive_objective": "Identify and document validation contracts at extension and parser boundaries, then verify them with safe unit tests"
      },
      {
        "id": "memory-safety-review",
        "title": "Review memory-safety assumptions",
        "defensive_objective": "Assess length, bounds, allocation, and lifetime assumptions in owned source code and vendor patches"
      },
      {
        "id": "patch-verification",
        "title": "Verify remediation evidence",
        "defensive_objective": "Compare vendor advisories, affected versions, fixes, and regression coverage without reproducing an exploit"
      },
      {
        "id": "security-token-design",
        "title": "Review security-token design",
        "defensive_objective": "Assess unpredictable generation, subject and operation binding, limited lifetime, single-use semantics and safe validation of security-sensitive tokens"
      },
      {
        "id": "error-response-design",
        "title": "Review secure error behavior",
        "defensive_objective": "Verify that failure responses minimize disclosure and that fallback paths preserve the original authorization context"
      }
    ]
  },
  "reports": [
    {
      "schema_version": "1.2.0",
      "organization": "Google",
      "researchers": [
        "Arvin Shivram (Brutecat)",
        "Theo"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "cloud-security"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "cloud-iam-review",
        "defensive-evidence-writing"
      ],
      "dates": {
        "published": {
          "value": "2026-09-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2026-07-18",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": "2026-07-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Article states resolution without a date."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://bughunters.google.com/blog/breaking-into-googles-gfile-for-100k",
          "title": "Breaking into Google's GFile for $100k",
          "type": "researcher",
          "author": "Arvin Shivram (Brutecat), published on Google Bug Hunters",
          "retrieved_at": "2026-10-03T16:00:54Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "report_identity"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://bughunters.google.com/blog/increasing-google-alphabet-vrp-rewards-up-to-151515",
          "title": "Increasing Google & Alphabet VRP rewards up to $151,515",
          "type": "vendor",
          "author": "Sam Erb and Krzysztof Kotowicz, Google",
          "retrieved_at": "2026-10-03T16:00:54Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "content_scope": "historical_defensive_summary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T16:00:54Z",
        "method": "Read both primary pages in the cloud browser after search returned no article body. Matched exact report labels to separate timeline awards. No target testing.",
        "limitations": [
          "Researcher narrative is hosted by Google and authored by a researcher who subsequently joined Google; conservatively classified as researcher-reported panel correspondence, without independent payment evidence.",
          "Resolution is stated, but deployment date and patch implementation are unspecified.",
          "The dollar denomination is inferred from Google’s July 2024 USD program announcement, approximately two years before the awards; it does not prove individual settlement.",
          "Mamba is a separately reported and separately awarded finding; its retrieval demonstration depends on Firefly. The combined demonstration is not an additional record or award."
        ]
      },
      "report_identity": {
        "kind": "source_label",
        "value": "Mamba",
        "source_id": "researcher-writeup",
        "evidence_location": "Timeline, separately labeled report and award entries"
      },
      "reward": {
        "amount": 37604.4,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Google Vulnerability Reward Program",
        "evidence_level": "researcher_reported_with_vendor_quote",
        "source_id": "researcher-writeup",
        "evidence_quote": "Panel awards $37,604.40 for Mamba",
        "evidence_location": "Timeline, July 24, 2026 Mamba entry",
        "usd_equivalent": null,
        "notes": "Separate report award; headline total is not used. Payment is unverified. USD follows the linked official denomination context. No component is counted separately."
      },
      "id": "google-mamba-temporary-output-isolation-2026",
      "title": "Google Mamba temporary outputs lacked access isolation",
      "product": "Mamba frame-metrics pipeline",
      "summary": "Mamba received a distinct USD 37,604.40 award. The case illustrates why temporary processing output needs explicit access isolation, with retrieval dependencies kept separate from standalone impact.",
      "root_cause": "Untrusted file selection reached privileged storage copying. Shared temporary outputs relied on obscurity, while diagnostic metadata weakened filename secrecy.",
      "impact": "Unauthenticated copying was possible, but demonstrated retrieval required the separately reported Firefly capability. The panel explicitly discounted difficult exploitation and additional access requirements.",
      "defensive_takeaways": [
        "Editorial lesson: isolate temporary outputs by authenticated principal and enforce access controls independent of filename secrecy.",
        "Editorial lesson: restrict file-source capabilities and minimize diagnostic disclosure; document dependencies before assigning standalone impact."
      ]
    },
    {
      "schema_version": "1.2.0",
      "organization": "Google",
      "researchers": [
        "Arvin Shivram (Brutecat)"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "cloud-security"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "cloud-iam-review",
        "defensive-evidence-writing"
      ],
      "dates": {
        "published": {
          "value": "2026-09-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2026-07-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": "2026-07-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Article states resolution without a date."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://bughunters.google.com/blog/breaking-into-googles-gfile-for-100k",
          "title": "Breaking into Google's GFile for $100k",
          "type": "researcher",
          "author": "Arvin Shivram (Brutecat), published on Google Bug Hunters",
          "retrieved_at": "2026-10-03T16:00:54Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "report_identity"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://bughunters.google.com/blog/increasing-google-alphabet-vrp-rewards-up-to-151515",
          "title": "Increasing Google & Alphabet VRP rewards up to $151,515",
          "type": "vendor",
          "author": "Sam Erb and Krzysztof Kotowicz, Google",
          "retrieved_at": "2026-10-03T16:00:54Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "content_scope": "historical_defensive_summary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T16:00:54Z",
        "method": "Read both primary pages in the cloud browser after search returned no article body. Matched exact report labels to separate timeline awards. No target testing.",
        "limitations": [
          "Researcher narrative is hosted by Google and authored by a researcher who subsequently joined Google; conservatively classified as researcher-reported panel correspondence, without independent payment evidence.",
          "Resolution is stated, but deployment date and patch implementation are unspecified.",
          "The dollar denomination is inferred from Google’s July 2024 USD program announcement, approximately two years before the awards; it does not prove individual settlement.",
          "The article demonstrates requests with a caller session but does not fully specify minimum account prerequisites; missing authorization is not treated as proof of anonymous Firefly access."
        ]
      },
      "report_identity": {
        "kind": "source_label",
        "value": "Firefly",
        "source_id": "researcher-writeup",
        "evidence_location": "Timeline, separately labeled report and award entries"
      },
      "reward": {
        "amount": 60000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Google Vulnerability Reward Program",
        "evidence_level": "researcher_reported_with_vendor_quote",
        "source_id": "researcher-writeup",
        "evidence_quote": "Panel awards $60,000 for Firefly",
        "evidence_location": "Timeline, July 24, 2026 Firefly entry",
        "usd_equivalent": null,
        "notes": "Separate report award; headline total is not used. Payment is unverified. USD follows the linked official denomination context. No component is counted separately."
      },
      "id": "google-firefly-worker-authority-storage-boundary-2026",
      "title": "Google Firefly confused worker authority and storage boundaries",
      "product": "Firefly partner-management API",
      "summary": "Firefly received a separately identified USD 60,000 award. The case illustrates how delegated worker authority and storage permissions can diverge from caller authorization.",
      "root_cause": "Missing caller authorization, unverified worker-result authority and unconstrained storage abstraction crossed service boundaries. The researcher questioned whether a narrowly named field actually limited backend authority.",
      "impact": "The researcher demonstrated storage reads and a local test-file write under a production identity. Broader access remained permission-dependent; universal infrastructure compromise is not established.",
      "defensive_takeaways": [
        "Editorial lesson: authenticate scheduler callbacks against the assigned worker and bind completion to an immutable task.",
        "Editorial lesson: enforce explicit storage capabilities rather than relying on field names; apply resource authorization before delegated execution."
      ]
    },
    {
      "schema_version": "1.1.0",
      "id": "google-chrome-angle-input-validation-2026",
      "title": "Chrome graphics input validation weakened an isolation boundary",
      "organization": "Google",
      "product": "Chrome / ANGLE",
      "researchers": [],
      "cve_ids": [
        "CVE-2026-14382"
      ],
      "cwe_mappings": [],
      "category_id": "client-security",
      "secondary_category_ids": [],
      "skillset_ids": [
        "browser-isolation-review",
        "untrusted-input-handling",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "summary": "One Chrome graphics report earned USD 250,000 across two award decisions.",
      "root_cause": "The graphics translation layer insufficiently validated untrusted input.",
      "impact": "Insufficiently validated graphics input could cross a browser security boundary; the vendor classified the issue High.",
      "defensive_takeaways": [
        "Validate untrusted graphics inputs at security boundaries and verify that mitigations cover all relevant input paths.",
        "Distinguish issue-status fixes from stable-release availability."
      ],
      "reward": {
        "amount": 250000,
        "currency": "USD",
        "scope": "single_vulnerability",
        "type": "bug_bounty",
        "awarding_organization": "Google / Chrome VRP",
        "status": "awarded",
        "evidence_level": "vendor_confirmed",
        "source_id": "vendor-report",
        "evidence_quote": "award you $25000.00 for this report … award you $225000.00 for this report",
        "evidence_location": "Public Chromium issue comments #25 and #30; ellipsis joins excerpts.",
        "usd_equivalent": null,
        "notes": "USD 25,000 on June 4 plus USD 225,000 on June 29 for one report. Case notices use $; USD is contextual from the official Chromium program source. No currency conversion or cash-receipt claim."
      },
      "dates": {
        "published": {
          "value": "2026-09-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": "Full report access restrictions removed; vendor release notice appeared earlier."
        },
        "public_disclosure": {
          "value": "2026-06-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Vendor release disclosure; full issue access was enabled later."
        },
        "reported": {
          "value": "2026-03-13",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": null
        },
        "awarded": {
          "value": "2026-06-29",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": null
        },
        "fixed": {
          "value": "2026-06-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Documented stable release; issue was marked Fixed 2026-05-27. Backport availability may differ."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2026-06-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Per-issue reward listed in the public release notice."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "vendor-report",
          "url": "https://issues.chromium.org/issues/492218546",
          "title": "Chromium issue 492218546",
          "type": "vendor",
          "author": "Google Chromium security team",
          "retrieved_at": "2026-10-02T16:08:00Z",
          "supports": [
            "reward",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html?m=1",
          "title": "Chrome Stable Channel Update for Desktop, 2026-06-30",
          "type": "vendor",
          "author": "Google Chrome team",
          "retrieved_at": "2026-10-02T16:08:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "cve",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://blog.chromium.org/2013/08/security-rewards-at-google-two.html",
          "title": "Security rewards at Google: Two MEEELLION Dollars Later",
          "type": "vendor",
          "author": "Chromium team",
          "retrieved_at": "2026-10-02T16:08:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "vendor-report",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T16:08:00Z",
        "method": "Public Chromium issue award/date metadata read in the cloud browser; official release corroborates exact per-issue total and CVE. No operational details retained.",
        "limitations": [
          "Case notices use dollar notation; USD denomination relies on official Chromium program context.",
          "Award decisions are established; payment completion is not.",
          "Fixed status and publicly available stable release are separate dates.",
          "Release credits an anonymous researcher. No identity or per-person split is inferred."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "openai-codex-repository-metadata-helper-trust-2026",
      "title": "Codex metadata collection trusted repository execution helpers",
      "organization": "OpenAI",
      "product": "Codex CLI and Codex Desktop",
      "researchers": [
        "maitai"
      ],
      "cve_ids": [
        "CVE-2026-19592"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-15",
          "basis": "source_explicit",
          "source_id": "vendor-cna",
          "note": "Explicit classification in the vendor-authored CNA record."
        }
      ],
      "category_id": "ai-security",
      "secondary_category_ids": [
        "client-security"
      ],
      "skillset_ids": [
        "ai-authority-boundaries",
        "integration-threat-modeling",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "summary": "ZDI awarded Doyensec USD 10,000 for this distinct Pwn2Own Berlin entry.",
      "root_cause": "Background metadata collection honored a repository-controlled filesystem-monitor helper without applying the intended approval and sandbox boundaries.",
      "impact": "The vendor confirms possible user-privilege code execution from preserved local repository settings. An ordinary Git clone does not preserve the required configuration.",
      "defensive_takeaways": [
        "Make background metadata collection independent of untrusted execution settings.",
        "Review ambient tool configuration as part of the application’s authority model."
      ],
      "reward": {
        "amount": 10000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Trend Micro Zero Day Initiative / Pwn2Own Berlin",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "competition-results",
        "evidence_quote": "They still earn $10,000 and 2 Master of Pwn points",
        "evidence_location": "Doyensec Codex entry in the dated daily results",
        "usd_equivalent": null,
        "notes": "Organizer records a collision with a vendor-known issue and a reduced USD 10,000 award. This is not a USD 40,000 first-round win. The vendor also credits Fudan researchers, without assigning them this competition award. Event rules explicitly denominate prizes in US currency; cash settlement is unverified."
      },
      "dates": {
        "published": {
          "value": "2026-09-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-cna",
          "note": "Vendor-authored technical CNA publication. ZDI published its advisory on September 10."
        },
        "public_disclosure": {
          "value": "2026-05-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Public competition demonstration and result, before technical CNA publication."
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original submission to the competition organizer is unknown. ZDI later lists 2026-09-09 as reported to vendor; this is a separate event, not the original submission date. That listed date also follows the September 1 CNA publication; the discrepancy is unresolved."
        },
        "awarded": {
          "value": "2026-05-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Individual-entry award reported in the day’s results."
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Vendor CNA lists fixed versions, but an exact release/deployment date was not established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2026-05-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "vendor-cna",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/19xxx/CVE-2026-19592.json",
          "title": "OpenAI CNA record for CVE-2026-19592",
          "type": "vendor",
          "author": "OpenAI CNA, distributed through the CVE Program",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "competition-results",
          "url": "https://www.zerodayinitiative.com/blog/2026/5/13/pwn2own-berlin-2026-day-one-results",
          "title": "Pwn2Own Berlin 2026 daily results",
          "type": "competition_organizer",
          "author": "Dustin Childs / Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "reward",
            "dates",
            "impact"
          ]
        },
        {
          "id": "competition-rules",
          "url": "https://www.zerodayinitiative.com/Pwn2OwnBerlin2026Rules.html",
          "title": "Pwn2Own Berlin 2026 rules",
          "type": "competition_organizer",
          "author": "Trend Micro Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "zdi-advisory",
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-650/",
          "title": "ZDI-26-650 Codex advisory",
          "type": "competition_organizer",
          "author": "Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "vendor-cna",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T17:23:00Z",
        "method": "Matched organizer result to the credited team, product and distinct CVE in the vendor CNA and Pwn2Own-tagged ZDI advisory; checked official currency and one-entry-per-target rules.",
        "limitations": [
          "Competition award, not an ordinary vendor bounty or a team’s total earnings.",
          "Original organizer submission and cash-transfer dates are unknown.",
          "Public demonstration, later vendor notification and technical publication are distinct events.",
          "The ZDI vendor-report date follows the CNA publication; it is preserved only as a qualified note, not treated as an original report date."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "openai-codex-repository-hook-execution-trust-2026",
      "title": "Codex automated Git operations trusted repository hook settings",
      "organization": "OpenAI",
      "product": "Codex Desktop",
      "researchers": [
        "Sina Kheirkhah"
      ],
      "cve_ids": [
        "CVE-2026-19590"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-427",
          "basis": "source_explicit",
          "source_id": "vendor-cna",
          "note": "Explicit classification in the vendor-authored CNA record."
        }
      ],
      "category_id": "ai-security",
      "secondary_category_ids": [
        "client-security"
      ],
      "skillset_ids": [
        "ai-authority-boundaries",
        "integration-threat-modeling",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "summary": "ZDI awarded Summoning Team USD 20,000 for this distinct Pwn2Own Berlin entry.",
      "root_cause": "Automated repository operations honored repository-local Git hook configuration outside the intended command-approval boundary.",
      "impact": "The vendor confirms possible user-privilege code execution when specially prepared local repository configuration is preserved. An ordinary Git clone does not preserve that configuration.",
      "defensive_takeaways": [
        "Treat repository-local execution settings as untrusted input.",
        "Apply execution policy to background tooling as well as user-visible agent commands."
      ],
      "reward": {
        "amount": 20000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Trend Micro Zero Day Initiative / Pwn2Own Berlin",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "competition-results",
        "evidence_quote": "earning $20,000 and 4 Master of Pwn points",
        "evidence_location": "Summoning Team Codex entry in the dated daily results",
        "usd_equivalent": null,
        "notes": "The successful second-round entry earned USD 20,000. The advertised first-round maximum and researcher’s other event entries are not this award. Event rules explicitly denominate prizes in US currency; cash settlement is unverified."
      },
      "dates": {
        "published": {
          "value": "2026-09-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-cna",
          "note": "Vendor-authored technical CNA publication. ZDI published its advisory on September 10."
        },
        "public_disclosure": {
          "value": "2026-05-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Public competition demonstration and result, before technical CNA publication."
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original submission to the competition organizer is unknown. ZDI later lists 2026-06-02 as reported to vendor; this is a separate event, not the original submission date."
        },
        "awarded": {
          "value": "2026-05-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Individual-entry award reported in the day’s results."
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Vendor CNA lists fixed versions, but an exact release/deployment date was not established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2026-05-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "vendor-cna",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/19xxx/CVE-2026-19590.json",
          "title": "OpenAI CNA record for CVE-2026-19590",
          "type": "vendor",
          "author": "OpenAI CNA, distributed through the CVE Program",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "competition-results",
          "url": "https://www.zerodayinitiative.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results",
          "title": "Pwn2Own Berlin 2026 daily results",
          "type": "competition_organizer",
          "author": "Dustin Childs / Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "reward",
            "dates",
            "impact"
          ]
        },
        {
          "id": "competition-rules",
          "url": "https://www.zerodayinitiative.com/Pwn2OwnBerlin2026Rules.html",
          "title": "Pwn2Own Berlin 2026 rules",
          "type": "competition_organizer",
          "author": "Trend Micro Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "zdi-advisory",
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-648/",
          "title": "ZDI-26-648 Codex advisory",
          "type": "competition_organizer",
          "author": "Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "vendor-cna",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T17:23:00Z",
        "method": "Matched organizer result to the credited team, product and distinct CVE in the vendor CNA and Pwn2Own-tagged ZDI advisory; checked official currency and one-entry-per-target rules.",
        "limitations": [
          "Competition award, not an ordinary vendor bounty or a team’s total earnings.",
          "Original organizer submission and cash-transfer dates are unknown.",
          "Public demonstration, later vendor notification and technical publication are distinct events."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "openai-codex-command-parser-approval-consistency-2026",
      "title": "Codex command approval relied on inconsistent parser semantics",
      "organization": "OpenAI",
      "product": "Codex CLI and Codex Desktop",
      "researchers": [
        "Emanuele Barbeno",
        "Cyrill Bannwart",
        "Yves Bieri",
        "Lukasz D.",
        "Urs Mueller"
      ],
      "cve_ids": [
        "CVE-2026-19591"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-150",
          "basis": "source_explicit",
          "source_id": "vendor-cna",
          "note": "Explicit classification in the vendor-authored CNA record."
        }
      ],
      "category_id": "injection",
      "secondary_category_ids": [
        "client-security"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "untrusted-input-handling",
        "ai-authority-boundaries",
        "patch-verification"
      ],
      "summary": "ZDI awarded Compass Security USD 40,000 for this distinct Pwn2Own Berlin entry.",
      "root_cause": "Command-safety analysis and the invoked shell interpreted control syntax differently, so the approval decision did not consistently describe the resulting operation.",
      "impact": "The vendor describes possible code execution with user privileges after untrusted repository instructions are followed. Shell availability and filesystem protections constrain impact; command approval failure does not itself disable the filesystem sandbox.",
      "defensive_takeaways": [
        "Keep safety classification consistent with actual command interpretation.",
        "Apply independent filesystem restrictions and protect security-sensitive configuration."
      ],
      "reward": {
        "amount": 40000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Trend Micro Zero Day Initiative / Pwn2Own Berlin",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "competition-results",
        "evidence_quote": "earning $40,000 and 4 Master of Pwn points",
        "evidence_location": "Compass Security Codex entry in the dated daily results",
        "usd_equivalent": null,
        "notes": "Single competition entry awarded to the Compass team; individual recipient splits and cash-transfer date are unknown. Event rules explicitly denominate prizes in US currency; cash settlement is unverified."
      },
      "dates": {
        "published": {
          "value": "2026-09-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-cna",
          "note": "Vendor-authored technical CNA publication. ZDI published its advisory on September 10."
        },
        "public_disclosure": {
          "value": "2026-05-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Public competition demonstration and result, before technical CNA publication."
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original submission to the competition organizer is unknown. ZDI later lists 2026-06-02 as reported to vendor; this is a separate event, not the original submission date."
        },
        "awarded": {
          "value": "2026-05-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Individual-entry award reported in the day’s results."
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Vendor CNA lists fixed versions, but an exact release/deployment date was not established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2026-05-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "vendor-cna",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/19xxx/CVE-2026-19591.json",
          "title": "OpenAI CNA record for CVE-2026-19591",
          "type": "vendor",
          "author": "OpenAI CNA, distributed through the CVE Program",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "competition-results",
          "url": "https://www.zerodayinitiative.com/blog/2026/5/13/pwn2own-berlin-2026-day-one-results",
          "title": "Pwn2Own Berlin 2026 daily results",
          "type": "competition_organizer",
          "author": "Dustin Childs / Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "reward",
            "dates",
            "impact"
          ]
        },
        {
          "id": "competition-rules",
          "url": "https://www.zerodayinitiative.com/Pwn2OwnBerlin2026Rules.html",
          "title": "Pwn2Own Berlin 2026 rules",
          "type": "competition_organizer",
          "author": "Trend Micro Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "zdi-advisory",
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-649/",
          "title": "ZDI-26-649 Codex advisory",
          "type": "competition_organizer",
          "author": "Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:23:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "vendor-cna",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T17:23:00Z",
        "method": "Matched organizer result to the credited team, product and distinct CVE in the vendor CNA and Pwn2Own-tagged ZDI advisory; checked official currency and one-entry-per-target rules.",
        "limitations": [
          "Competition award, not an ordinary vendor bounty or a team’s total earnings.",
          "Original organizer submission and cash-transfer dates are unknown.",
          "Public demonstration, later vendor notification and technical publication are distinct events."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "apple-pcc-boot-archive-path-validation-2026",
      "title": "Apple PCC startup archive processing lacked path confinement",
      "organization": "Apple",
      "product": "Private Cloud Compute server software",
      "researchers": [
        "Drinor Selmanaj"
      ],
      "cve_ids": [
        "CVE-2026-20685"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-22",
          "basis": "source_explicit",
          "source_id": "primary",
          "note": "Researcher explicitly identifies the path-traversal weakness class."
        }
      ],
      "category_id": "cloud-security",
      "secondary_category_ids": [
        "ai-security"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "secure-parser-review",
        "integration-threat-modeling",
        "patch-verification"
      ],
      "summary": "Sentry documents a USD 150,000 award to Drinor Selmanaj for CVE-2026-20685.",
      "root_cause": "Privileged startup archive handling did not adequately confine output paths; mutable configuration could undermine runtime integrity assumptions.",
      "impact": "Researcher demonstrated configuration changes and telemetry disclosure in Apple’s virtual environment. Apple confirms potential sensitive-information leakage from a privileged network position.",
      "defensive_takeaways": [
        "Confine archive output and authenticate provisioning inputs.",
        "Include security-relevant mutable configuration in integrity review.",
        "Use the fixed PCC release and preserve the vendor’s impact prerequisites."
      ],
      "reward": {
        "amount": 150000,
        "currency": "USD",
        "scope": "single_vulnerability",
        "type": "bug_bounty",
        "awarding_organization": "Apple Security Bounty",
        "status": "awarded",
        "evidence_level": "researcher_reported_with_vendor_quote",
        "source_id": "primary",
        "evidence_quote": "Drinor was awarded $150,000 for CVE-2026-20685",
        "evidence_location": "Article opening; researcher-hosted award-offer image provides corroboration",
        "usd_equivalent": null,
        "notes": "Individual CVE award attributed to Selmanaj. Researcher-hosted Apple offer is not vendor-hosted payment confirmation. USD follows official program context; cash settlement and award date are unverified."
      },
      "dates": {
        "published": {
          "value": "2026-07-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "publication-index",
          "note": "Sentry’s own article listing supplies the date."
        },
        "public_disclosure": {
          "value": "2026-05-18",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-cna",
          "note": "CVE publication timestamp; detailed researcher article appeared later."
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Apple identifies PCC Release 5E290.3 as fixed; exact release/deployment date was not established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://blog.sentry.security/beyond-prompt-injection-hacking-apples-private-cloud-compute/",
          "title": "Beyond Prompt Injection: Hacking Apple's Private Cloud Compute",
          "type": "researcher",
          "author": "Drinor Selmanaj / Sentry",
          "retrieved_at": "2026-10-02T17:03:00Z",
          "supports": [
            "reward",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "publication-index",
          "url": "https://blog.sentry.security/",
          "title": "Sentry article listing",
          "type": "researcher",
          "author": "Sentry",
          "retrieved_at": "2026-10-02T17:03:00Z",
          "supports": [
            "dates"
          ]
        },
        {
          "id": "vendor-cna",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/20xxx/CVE-2026-20685.json",
          "title": "Apple CNA record for CVE-2026-20685",
          "type": "vendor",
          "author": "Apple CNA, distributed through the CVE Program",
          "retrieved_at": "2026-10-02T17:03:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "award-image",
          "url": "https://storage.ghost.io/c/3c/85/3c852989-e4b5-4868-8226-9c9bebdfb8f2/content/images/2026/07/150k-post2.png",
          "title": "Researcher-hosted Apple award-offer graphic",
          "type": "researcher",
          "author": "Sentry",
          "retrieved_at": "2026-10-02T17:03:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.apple.com/nz/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/",
          "title": "Apple Security Bounty US-dollar program context",
          "type": "vendor",
          "author": "Apple Newsroom",
          "retrieved_at": "2026-10-02T17:03:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T17:03:00Z",
        "method": "Read the researcher article, publication index, full Apple-authored CNA record and official currency context; reviewed the researcher-hosted offer graphic.",
        "limitations": [
          "Research was demonstrated in Apple’s virtual environment; production was not tested by the researcher.",
          "No confirmed production prompt-content leakage is claimed here.",
          "Award attribution is researcher-hosted; vendor CNA evidence corroborates the vulnerability and fixed version, not payout.",
          "No exact report, award, fix deployment or payment date was established."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-device-authorization-client-scope-binding-2026",
      "title": "Google device grants lost client and permission binding",
      "organization": "Google",
      "product": "Google OAuth device authorization",
      "researchers": [
        "weirdmachine64"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "authorization"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "integration-threat-modeling",
        "authorization-modeling",
        "security-token-design"
      ],
      "summary": "A researcher reports USD 13,337 for a device-grant authorization-boundary failure.",
      "root_cause": "The account completing authentication could authorize a different requesting device, while client identity and permissions were not preserved through the grant. The researcher reasoned about consistency between initial authorization and final token authority. Cross-device sign-in alone is expected behavior; the reported failure was loss of the intended recipient and permission binding.",
      "impact": "The author reports third-party account access, elevated permissions and mailbox access. Reduced-interaction behavior required a signed-in user opening a link and relevant prior consent. Universal reach, unrestricted persistence and uniform absence of alerts are not independently established.",
      "defensive_takeaways": [
        "Editorial lesson: preserve one server-side authorization decision across device identity, client identity, subject and permitted actions; every completion path must respect it.",
        "The researcher recommends server-side grant binding and explicit device confirmation. These are proposed controls, not verified descriptions of the deployed fix."
      ],
      "reward": {
        "amount": 13337,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "Google Vulnerability Reward Program",
        "status": "awarded",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "Rewarded $13,337",
        "evidence_location": "Disclosure Timeline, April 2, 2026 row",
        "usd_equivalent": null,
        "notes": "One chain award, counted once. The researcher uses $. USD is inferred from Google’s March 2017 program-wide denomination statement, about nine years before the April 2026 award. That context does not independently establish this individual award’s currency or settlement; cash receipt is unverified."
      },
      "dates": {
        "published": {
          "value": "2026-07-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2026-02-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2026-04-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Researcher records marked-fixed status on March 28, 2026; deployment date is not independently established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html",
          "title": "Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking",
          "type": "researcher",
          "author": "weirdmachine64",
          "retrieved_at": "2026-10-03T17:39:29Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://security.googleblog.com/2017/03/vrp-news-from-nullcon.html",
          "title": "VRP news from Nullcon",
          "type": "vendor",
          "author": "Google Security Blog",
          "retrieved_at": "2026-10-03T17:39:29Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T17:39:29Z",
        "method": "Fresh-read the primary narrative and award timeline with the older vendor currency context; explicitly qualified the temporal gap and inference. No testing.",
        "limitations": [
          "No independently reviewed vendor evidence establishes technical reach, award or settlement.",
          "The March 28, 2026 marked-fixed status does not establish deployment timing or patch contents.",
          "Specific client permissions, existing consent and downstream token acceptance constrain the reported impact; one broad title does not prove every integration was affected."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "redis-replication-interpreter-lifetime-2026",
      "title": "Redis replication state changes invalidated an active interpreter",
      "organization": "Redis",
      "product": "Redis replication and Lua function execution",
      "researchers": [
        "Yoni Sherez"
      ],
      "cve_ids": [
        "CVE-2026-23631"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-416",
          "basis": "source_explicit",
          "source_id": "vendor-cve",
          "note": "Use After Free classification is explicit in the vendor CNA record."
        }
      ],
      "category_id": "memory-safety",
      "secondary_category_ids": [
        "cloud-security",
        "business-logic"
      ],
      "skillset_ids": [
        "memory-safety-review",
        "concurrency-reasoning",
        "integration-threat-modeling",
        "patch-verification"
      ],
      "summary": "Wiz confirms a USD 30,000 individual competition award for Yoni Sherez’s Redis entry, identified as CVE-2026-23631.",
      "root_cause": "The researcher compared ordinary command handling with replication-related state changes during ongoing function execution. The latter did not preserve equivalent lifetime checks, so interpreter state could be released while still in use. The failed invariant was that background synchronization must not invalidate objects needed by active work.",
      "impact": "Code execution was demonstrated in the competition. The vendor limits exposure to authenticated access and replicas configured, or configurable, for writes. It reported Redis Cloud patched by its May 2026 announcement. These conditions do not establish equivalent exposure across all deployments.",
      "defensive_takeaways": [
        "Apply lifetime invariants to background synchronization and administrative state transitions as well as normal request paths.",
        "Treat reentrant event handling as a concurrency boundary even in a nominally single-threaded service.",
        "Review replica configuration and scripting privileges, and verify fixed versions against the vendor’s product-specific guidance."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Wiz / ZeroDay.cloud",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "competition-results",
        "evidence_quote": "$30,000 awarded",
        "evidence_location": "Redis: Yoni Sherez entry in the organizer’s Day 1 results",
        "usd_equivalent": null,
        "notes": "One individually identified competition entry. The organizer uses $; its current rules establish US-dollar notation but concern 2026, not an archived 2025 rules snapshot. Exact award decision and cash settlement are unknown."
      },
      "dates": {
        "published": {
          "value": "2026-06-02",
          "precision": "day",
          "basis": "inferred",
          "source_id": "researcher-report",
          "note": "Article displays June 2; 2026 is inferred from its completed May 5, 2026 remediation timeline."
        },
        "public_disclosure": {
          "value": "2025-12-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-tracker",
          "note": "Public competition demonstration; separate from later vendor advisory and technical publication."
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Exact initial report to the vendor is not stated; the tracker dates the competition entry, not vendor receipt."
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": "2026-05-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-release",
          "note": "Official Redis 8.6.3 release names the CVE. Other supported release lines are listed separately by the vendor; this date is not a customer deployment date."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2025-12-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Organizer recap confirms the per-entry award; decision and payment dates remain unknown."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "competition-results",
          "url": "https://www.wiz.io/blog/wiz-zeroday-cloud-hacking-competition-behind-the-scenes",
          "title": "ZeroDay.cloud 2025 individual competition results",
          "type": "competition_organizer",
          "author": "Nir Ohfeld / Wiz Research",
          "retrieved_at": "2026-10-02T20:00:00Z",
          "supports": [
            "reward",
            "dates"
          ]
        },
        {
          "id": "competition-tracker",
          "url": "https://www.zeroday.cloud/vulnerability-tracker",
          "title": "ZeroDay.cloud vulnerability tracker",
          "type": "competition_organizer",
          "author": "Wiz / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T20:00:00Z",
          "supports": [
            "dates",
            "cve"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.zeroday.cloud/rules",
          "title": "ZeroDay.cloud current rules: US-dollar denomination",
          "type": "competition_organizer",
          "author": "Wiz",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "researcher-report",
          "url": "https://www.zeroday.cloud/blog/redis-cve-2026-23631-dark-replica",
          "title": "DarkReplica (CVE-2026-23631): Redis Use-After-Free Leads to Post-Auth RCE",
          "type": "researcher",
          "author": "Yoni Sherez / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T20:00:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-advisory",
          "url": "https://github.com/redis/redis/security/advisories/GHSA-8ghh-qpmp-7826",
          "title": "Redis Lua lifetime advisory GHSA-8ghh-qpmp-7826",
          "type": "vendor",
          "author": "Redis",
          "retrieved_at": "2026-10-02T20:00:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-cve",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/23xxx/CVE-2026-23631.json",
          "title": "CVE-2026-23631 CNA record",
          "type": "vendor",
          "author": "Redis / GitHub CNA",
          "retrieved_at": "2026-10-02T20:00:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-release",
          "url": "https://github.com/redis/redis/releases/tag/8.6.3",
          "title": "Redis 8.6.3 security release",
          "type": "vendor",
          "author": "Redis",
          "retrieved_at": "2026-10-02T20:00:00Z",
          "supports": [
            "dates",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-product-guidance",
          "url": "https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/",
          "title": "Redis May 2026 security advisory and product remediation table",
          "type": "vendor",
          "author": "Riaz Lakhani / Redis",
          "retrieved_at": "2026-10-02T20:00:00Z",
          "supports": [
            "dates",
            "impact",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "researcher-report",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T20:00:00Z",
        "method": "Matched the individual award to the exact tracker CVE, researcher article and vendor credit. Cross-checked configuration prerequisites, CNA classification and the official release date.",
        "limitations": [
          "The tracker spells the researcher’s surname Sharez; the matching CVE, vendor credit and researcher article identify Yoni Sherez.",
          "The advisory’s structured affected field starts at 7.0.0 and says patched versions TBD, while its prose is broader; vendor guidance and the official release identify corrected versions. No universal version range is inferred.",
          "Competition code execution and vendor-qualified deployment exposure are distinct claims; the vendor says it had no evidence of customer exploitation at publication.",
          "Exact initial vendor-report, award-decision and cash-settlement dates are unknown. The June publication year is inferred.",
          "USD context comes from current organizer rules, explicitly distinct from an archived 2025 rules snapshot."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "redis-deserialization-object-ownership-2026",
      "title": "Redis deserialization cleanup violated object-ownership invariants",
      "organization": "Redis",
      "product": "Redis serialized-object loading",
      "researchers": [
        "Emil Lerner"
      ],
      "cve_ids": [
        "CVE-2026-25243"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-122",
          "basis": "source_explicit",
          "source_id": "vendor-cve",
          "note": "Vendor CNA category retained as published; the researcher describes double-free mechanisms within this broader advisory."
        }
      ],
      "category_id": "memory-safety",
      "secondary_category_ids": [
        "cloud-security"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "memory-safety-review",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "summary": "Wiz confirms USD 30,000 for Emil Lerner’s Redis competition entry. Two related disclosed defects remain one awarded entry.",
      "root_cause": "The researcher traced object ownership through deserialization and failure cleanup. Validation and conversion interpreted legacy data differently, while another cleanup path released an object still owned elsewhere. Both defects violated the invariant that each allocation is released exactly once; accepting a data-import request did not make its contents trustworthy.",
      "impact": "The researcher demonstrated code execution in the competition. The vendor confirms possible execution under Redis-process authority for an authenticated user with import permission. Host or tenant reach depends on deployment privileges and isolation; it is not established for every Redis installation.",
      "defensive_takeaways": [
        "Make ownership transfer and cleanup responsibility explicit on success and failure paths.",
        "Require validators and converters to interpret the same serialized representation consistently.",
        "Follow vendor patch guidance; restrict unnecessary import permissions using access controls while remediation is assessed."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Wiz / ZeroDay.cloud",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "competition-results",
        "evidence_quote": "$30,000 awarded",
        "evidence_location": "Redis: Emil Lerner entry in the organizer’s Day 1 results",
        "usd_equivalent": null,
        "notes": "One individually identified competition entry. The organizer uses $; its current rules establish US-dollar notation but concern 2026, not an archived 2025 rules snapshot. Exact award decision and cash settlement are unknown."
      },
      "dates": {
        "published": {
          "value": "2026-06-02",
          "precision": "day",
          "basis": "inferred",
          "source_id": "researcher-report",
          "note": "The article displays June 2; 2026 is inferred from its completed May 5, 2026 remediation timeline."
        },
        "public_disclosure": {
          "value": "2025-12-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-tracker",
          "note": "Public competition demonstration; separate from later vendor advisory and technical publication."
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Exact initial report to the vendor is not stated; the tracker dates the competition entry, not vendor receipt."
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": "2026-05-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-release",
          "note": "Official Redis 8.6.3 release names the CVE. Researcher also identifies fixed versions in four other maintained series."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2025-12-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Organizer recap confirms the per-entry award; decision and payment dates remain unknown."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "competition-results",
          "url": "https://www.wiz.io/blog/wiz-zeroday-cloud-hacking-competition-behind-the-scenes",
          "title": "ZeroDay.cloud 2025 individual competition results",
          "type": "competition_organizer",
          "author": "Nir Ohfeld / Wiz Research",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "reward",
            "dates"
          ]
        },
        {
          "id": "competition-tracker",
          "url": "https://www.zeroday.cloud/vulnerability-tracker",
          "title": "ZeroDay.cloud vulnerability tracker",
          "type": "competition_organizer",
          "author": "Wiz / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "dates",
            "cve"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.zeroday.cloud/rules",
          "title": "ZeroDay.cloud current rules: US-dollar denomination",
          "type": "competition_organizer",
          "author": "Wiz",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "researcher-report",
          "url": "https://www.zeroday.cloud/blog/redis-cve-2026-25243-deep-dive",
          "title": "CVE-2026-25243: Two Redis RESTORE Bugs Leading to RCE",
          "type": "researcher",
          "author": "Emil Lerner / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-advisory",
          "url": "https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4",
          "title": "Redis serialized-value validation advisory GHSA-c8h9-259x-jff4",
          "type": "vendor",
          "author": "Redis",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-cve",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/25xxx/CVE-2026-25243.json",
          "title": "CVE-2026-25243 CNA record",
          "type": "vendor",
          "author": "Redis / GitHub CNA",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-release",
          "url": "https://github.com/redis/redis/releases/tag/8.6.3",
          "title": "Redis 8.6.3 security release",
          "type": "vendor",
          "author": "Redis",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "dates",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "researcher-report",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T19:21:00Z",
        "method": "Matched the individual award, exact CVE tracker row, named researcher explanation and vendor advisory. Checked release metadata for the fix date and kept two defects inside the single awarded entry.",
        "limitations": [
          "The vendor advisory also credits Joseph Surin; the reviewed award names Emil Lerner only, so no reward allocation to the additional credited researcher is inferred.",
          "The advisory’s patched-version field still says TBD, while the official 8.6.3 release explicitly lists the CVE as fixed; the CNA affected range also excludes 8.6.3.",
          "The researcher explains double-free mechanisms, while the CNA supplies CWE-122; neither classification is silently substituted for the other.",
          "Original vendor-report, award decision and settlement dates remain unknown; June 2 publication year is inferred.",
          "Current rules provide explicit USD context but are not the archived 2025 rules."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "meta-service-identity-secrets-trust-boundary-2026",
      "title": "Meta service-identity exposure amplified by excessive secret access",
      "organization": "Meta",
      "product": "Internal development and cloud-service integrations",
      "researchers": [
        "Preben Ver Eecke",
        "Sectricity"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "cloud-security",
      "secondary_category_ids": [
        "authorization",
        "authentication"
      ],
      "skillset_ids": [
        "cloud-iam-review",
        "machine-identity-governance",
        "secrets-containment",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "A researcher organization reports a $150,000 base award for an exposed service identity with excessive downstream integration authority.",
      "root_cause": "An exposed service identity had unnecessarily broad access to secrets, with downstream integration credentials extending the potential impact into private source repositories. Apply strong service authentication, minimize identity permissions, and separate trust between integrations.",
      "impact": "Researchers report potential read/write access to 507 private repositories; their write-up says they confirmed the count and did not clone or browse repository contents.",
      "defensive_takeaways": [
        "Require authenticated, explicitly authorized access to service identities.",
        "Constrain secret access and integration privileges to the minimum required.",
        "Document exposure without copying private customer or source data."
      ],
      "reward": {
        "amount": 150000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "Meta",
        "status": "awarded",
        "evidence_level": "researcher_reported_with_vendor_quote",
        "source_id": "primary",
        "evidence_quote": "After reviewing this issue, we have decided to award you a bounty of $150000.",
        "evidence_location": "Meta response reproduced by researcher organization",
        "usd_equivalent": null,
        "notes": "Use the $150,000 base award. The headline says $157K, but the stated 5% bonus would imply $157,500; exact total is not asserted. USD normalization of the dollar-denominated Meta award; the reproduced individual message uses $."
      },
      "dates": {
        "reported": {
          "value": "2026-03-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2026-04-29",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The source says mitigated, not that a final software fix was released."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": "2026-03-23",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Triaged and mitigated according to the researcher timeline."
        },
        "published": {
          "value": "2026-05-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Earliest public disclosure has not been independently established."
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://sectricity.com/blog/misconfigured-grafana-507-private-meta-repos/",
          "title": "Meta service-identity exposure amplified by excessive secret access",
          "type": "researcher",
          "author": "Preben Ver Eecke, Sectricity",
          "retrieved_at": "2026-10-02T03:54:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "source-2",
          "url": "https://sectricity.com/about/method-ethics/",
          "title": "Supporting primary disclosure source",
          "type": "researcher",
          "author": "Preben Ver Eecke, Sectricity",
          "retrieved_at": "2026-10-02T03:54:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T03:54:00Z",
        "method": "Primary public sources read; reward distinguished from maximums and aggregates. Historical defensive summary only; no vulnerability testing performed.",
        "limitations": [
          "Headline states $157K, while $150,000 plus 5% arithmetically equals $157,500; use the undisputed $150,000 base and preserve this discrepancy",
          "Vendor response is reproduced by the researcher organization, not independently hosted by Meta",
          "The exposed Grafana dashboard was a discovery signal, not established as the underlying rewarded vulnerability"
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-application-integration-authorization-boundaries-2026",
      "title": "Google Application Integration mixed resource and service authority",
      "organization": "Google",
      "product": "Google Cloud Application Integration",
      "researchers": [
        "Arvin Shivram (Brutecat)"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "cloud-security"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "cloud-iam-review",
        "defensive-evidence-writing"
      ],
      "summary": "A researcher reports a $75,000 base award for a distinct Application Integration report.",
      "root_cause": "Resource-ownership checks and task-authority checks were inconsistent. The researcher compared customer-project permissions with the authority of backend integration services, identifying gaps between authorized customer activity and privileged service operations.",
      "impact": "The authenticated-user research reports cross-project access and test execution. Production compromise potential was reportedly confirmed by Google, which stopped further testing; completed code execution in production was not demonstrated. Wider impact remains unverified.",
      "defensive_takeaways": [
        "Editorial lesson: authorize the actual resource owner at every service boundary rather than relying on an enclosing project context.",
        "Editorial lesson: independently constrain service-task authority even when the initiating user may legitimately configure an integration.",
        "Editorial lesson: use cross-tenant negative tests and track observed effects separately from vendor-assessed potential."
      ],
      "reward": {
        "amount": 75000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "2026-04-28 - Panel awards $75,000.",
        "evidence_location": "Timeline (2nd RCE)",
        "usd_equivalent": null,
        "notes": "Only the second report’s base award; excludes the later $13,337 and first report. USD remains contextual: Google’s July 2024 USD-denominated VRP announcement and October 2024 Cloud-program continuity statement, not settlement evidence.",
        "type": "bug_bounty",
        "awarding_organization": "Google"
      },
      "dates": {
        "published": {
          "value": "2026-05-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Visible article header supplies May 22, 2026 and author Arvin Shivram."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2026-03-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2026-04-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://brutecat.com/articles/google-cloud-rce/",
          "title": "StubZero: $148,337 RCE in Google Cloud Production",
          "type": "researcher",
          "author": "Arvin Shivram (Brutecat)",
          "retrieved_at": "2026-10-03T02:35:33Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "google-currency",
          "url": "https://bughunters.google.com/blog/increasing-google-alphabet-vrp-rewards-up-to-151515",
          "title": "Increasing Google & Alphabet VRP rewards up to $151,515",
          "type": "vendor",
          "author": "Sam Erb and Krzysztof Kotowicz / Google",
          "retrieved_at": "2026-10-03T02:35:33Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "cloud-program-continuity",
          "url": "https://cloud.google.com/blog/products/identity-security/google-cloud-launches-new-vulnerability-rewards-program",
          "title": "Introducing Google Cloud’s new Vulnerability Reward Program",
          "type": "vendor",
          "author": "Michael Cote and Sri Tulasiram / Google Cloud",
          "retrieved_at": "2026-10-03T02:35:33Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T02:35:33Z",
        "method": "Read primary article text, including the dated byline, and official Google sources. The July 2024 USD announcement was read in rendered browser text. No target testing.",
        "limitations": [
          "Award and vendor impact assessment are researcher-published claims, not independently reviewed vendor correspondence.",
          "The article-level CVE is not assigned here because its scope across the separate reports is ambiguous.",
          "No precise fix date, payment occurrence or settlement date is established.",
          "Currency inference uses 2024 program context, about two years before the award. The current Cloud policy uses a dollar symbol without an explicit USD statement; no independent settlement evidence is claimed."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "postgresql-pgcrypto-buffer-capacity-validation-2026",
      "title": "PostgreSQL cryptographic parsing omitted a buffer-capacity check",
      "organization": "PostgreSQL",
      "product": "PostgreSQL pgcrypto extension",
      "researchers": [
        "Team Xint Code"
      ],
      "cve_ids": [
        "CVE-2026-2005"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-122",
          "basis": "source_explicit",
          "source_id": "vendor-cve",
          "note": "Explicit heap-based buffer overflow classification in the CNA record."
        }
      ],
      "category_id": "memory-safety",
      "secondary_category_ids": [
        "cloud-security"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "memory-safety-review",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "summary": "The organizer awarded Team Xint Code USD 30,000 for this individually identified ZeroDay.cloud 2025 competition entry.",
      "root_cause": "Cryptographic message parsing copied a derived key length into a fixed-capacity destination without verifying that the destination was large enough.",
      "impact": "The PostgreSQL advisory confirms possible code execution under the database operating-system account. The vendor CVE record limits the prerequisite to permission to install the extension or supply ciphertext to an existing installation.",
      "defensive_takeaways": [
        "Validate derived lengths against destination capacity before copying data.",
        "Review extension permissions and least-privilege database process identities.",
        "Use vendor release evidence to verify remediation rather than replaying an exploit."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Wiz / ZeroDay.cloud",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "competition-results",
        "evidence_quote": "$30,000 awarded",
        "evidence_location": "PostgreSQL: Team Xint Code entry in the organizer's Day 1 results",
        "usd_equivalent": null,
        "notes": "One entry award, excluding the team’s other database entries. The results use $; USD denomination is contextualized by the organizer’s current rules, which concern 2026 rather than an archived 2025 rules snapshot. No conversion or cash-settlement claim is made."
      },
      "dates": {
        "published": {
          "value": "2026-05-04",
          "precision": "day",
          "basis": "inferred",
          "source_id": "researcher-report",
          "note": "Displayed May 4; year inferred from the completed 2026 remediation timeline."
        },
        "public_disclosure": {
          "value": "2025-12-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-tracker",
          "note": "Public competition demonstration. Subsequent CVE/advisory publication and full technical article are separate events."
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The researcher identifies the December 10–11 event; no exact initial vendor-report date is stated. The tracker dates the public entry December 10."
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": "2026-02-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-advisory",
          "note": "Vendor patch release, not proof of deployment by every customer."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2025-12-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Dated organizer recap announces the exact entry award; decision and transfer dates remain unknown."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "researcher-report",
          "url": "https://www.zeroday.cloud/blog/postgres-xint",
          "title": "CVE-2026-2005: PostgreSQL pgcrypto heap buffer overflow leading to RCE",
          "type": "researcher",
          "author": "Team Xint Code / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "competition-results",
          "url": "https://www.wiz.io/blog/wiz-zeroday-cloud-hacking-competition-behind-the-scenes",
          "title": "ZeroDay.cloud 2025 individual competition results",
          "type": "competition_organizer",
          "author": "Nir Ohfeld / Wiz Research",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "reward",
            "dates"
          ]
        },
        {
          "id": "competition-tracker",
          "url": "https://www.zeroday.cloud/vulnerability-tracker",
          "title": "ZeroDay.cloud vulnerability tracker",
          "type": "competition_organizer",
          "author": "Wiz / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "dates",
            "cve"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.zeroday.cloud/rules",
          "title": "ZeroDay.cloud current rules: US-dollar denomination",
          "type": "competition_organizer",
          "author": "Wiz",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "vendor-advisory",
          "url": "https://www.postgresql.org/support/security/CVE-2026-2005/",
          "title": "PostgreSQL CVE-2026-2005 security advisory",
          "type": "vendor",
          "author": "PostgreSQL",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-cve",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/2xxx/CVE-2026-2005.json",
          "title": "CVE-2026-2005 CNA record",
          "type": "vendor",
          "author": "PostgreSQL CNA / CVE Program",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "dates",
            "impact",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "researcher-report",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T18:12:00Z",
        "method": "Read the named researcher report, organizer CVE tracker and per-entry award result; cross-checked vendor advisories and CNA records. Currency context is explicitly distinguished from award evidence. No vulnerability testing performed.",
        "limitations": [
          "The event demonstration is distinct from the February 12, 2026 vendor advisory and May research article.",
          "The source identifies Team Xint Code; no allocation to named individual recipients is established.",
          "The article shows May 4 without a year; 2026 is inferred from its explicitly dated remediation timeline.",
          "Exact award decision and funds-transfer dates are not reported; December 16 is the dated organizer announcement.",
          "Current rules establish program US-dollar notation but are not an archived snapshot of the 2025 rules."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "postgresql-multibyte-validation-cve-2026-2006",
      "title": "PostgreSQL text-encoding invariant failure caused memory corruption",
      "organization": "PostgreSQL",
      "product": "PostgreSQL text handling and pgcrypto extension",
      "researchers": [
        "Paul Gerste",
        "Moritz Sanft",
        "Team Bugz Bunnies"
      ],
      "cve_ids": [
        "CVE-2026-2006"
      ],
      "cwe_mappings": [],
      "category_id": "memory-safety",
      "secondary_category_ids": [
        "injection"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "encoding-invariant-review",
        "memory-safety-review",
        "integration-threat-modeling",
        "patch-verification"
      ],
      "summary": "A PostgreSQL encoding-validation failure earned Team Bugz Bunnies a $30,000 individual-entry award at ZeroDay.cloud. The vendor subsequently issued CVE-2026-2006.",
      "root_cause": "A trusted extension did not uphold a database-wide text-encoding invariant, while downstream text routines relied on that invariant for memory-safe length calculations. Defensive reviews should verify contracts across parser and extension boundaries.",
      "impact": "Vendor confirms that an authenticated database user could reach code execution with the database operating-system account's privileges.",
      "defensive_takeaways": [
        "Validate encoding contracts at every trusted extension boundary.",
        "Avoid relying on unverified text invariants for memory-length calculations.",
        "Apply supported vendor fixes and retain regression coverage."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Wiz / ZeroDay.cloud",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "primary",
        "evidence_quote": "PostgreSQL: Team Bugz Bunnies (Paul Gerste & Moritz Sanft) – SUCCESSFUL – $30,000 awarded",
        "evidence_location": "Day 2 results, PostgreSQL Team Bugz Bunnies entry",
        "usd_equivalent": null,
        "notes": "Per-finding competition award to a team, not a vendor bounty or the team's combined event earnings. Exact cash-transfer date is unknown. USD normalization of the organizer's dollar-denominated competition award."
      },
      "dates": {
        "reported": {
          "value": "2025-12-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "source-3",
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": "2026-02-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "source-4",
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2025-12-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Organizer recap announces the individual entry award; exact award/transfer date not published."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "published": {
          "value": "2026-05-04",
          "precision": "day",
          "basis": "inferred",
          "source_id": "source-3",
          "note": "On-stage demonstration and vendor disclosure are explicitly December 11, 2025. Organizer payout recap was published December 16; cash transfer date is not stated. Detailed researcher article is dated May 4, with year contextualized by its 2026 fix timeline."
        },
        "public_disclosure": {
          "value": "2025-12-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "source-2",
          "note": "Public competition demonstration; detailed technical publication followed in 2026."
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.wiz.io/blog/wiz-zeroday-cloud-hacking-competition-behind-the-scenes",
          "title": "PostgreSQL text-encoding invariant failure caused memory corruption",
          "type": "competition_organizer",
          "author": "Wiz / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T03:54:00Z",
          "supports": [
            "reward",
            "dates"
          ]
        },
        {
          "id": "source-2",
          "url": "https://www.zeroday.cloud/vulnerability-tracker",
          "title": "Supporting primary disclosure source",
          "type": "competition_organizer",
          "author": "Wiz / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T03:54:00Z",
          "supports": [
            "cve",
            "dates"
          ]
        },
        {
          "id": "source-3",
          "url": "https://www.zeroday.cloud/blog/postgresql-cve-2026-2005-deep-dive",
          "title": "Supporting primary disclosure source",
          "type": "researcher",
          "author": "Paul Gerste, Moritz Sanft, Team Bugz Bunnies",
          "retrieved_at": "2026-10-02T03:54:00Z",
          "supports": [
            "root_cause",
            "impact",
            "dates",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "source-4",
          "url": "https://www.postgresql.org/support/security/CVE-2026-2006/",
          "title": "PostgreSQL CVE-2026-2006 vendor advisory",
          "type": "vendor",
          "author": "PostgreSQL Global Development Group",
          "retrieved_at": "2026-10-02T03:54:00Z",
          "supports": [
            "cve",
            "root_cause",
            "impact",
            "dates",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T03:54:00Z",
        "method": "Primary public sources read; reward distinguished from maximums and aggregates. Historical defensive summary only; no vulnerability testing performed.",
        "limitations": [
          "This is a per-finding competition award, not a traditional vendor bounty; keep award_type visible",
          "Do not count the team's $40,000 combined Grafana and PostgreSQL earnings as this finding's reward",
          "Actual funds-transfer date not published"
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "mariadb-json-normalization-buffer-capacity-2026",
      "title": "MariaDB JSON normalization exceeded allocated buffer capacity",
      "organization": "MariaDB",
      "product": "MariaDB Server JSON schema validation",
      "researchers": [
        "Team Xint Code"
      ],
      "cve_ids": [
        "CVE-2026-32710"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-122",
          "basis": "source_explicit",
          "source_id": "vendor-cve",
          "note": "Explicit heap-based buffer overflow classification in the CNA record."
        }
      ],
      "category_id": "memory-safety",
      "secondary_category_ids": [
        "cloud-security"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "memory-safety-review",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "summary": "The organizer awarded Team Xint Code USD 30,000 for this individually identified ZeroDay.cloud 2025 competition entry.",
      "root_cause": "JSON normalization copied variable-length text into an undersized allocation. The fix uses storage management that grows the buffer to fit the value.",
      "impact": "An authenticated database user could crash the server. The researcher demonstrated code execution at the event; the vendor-authored CVE record qualifies that outcome as dependent on unusually controlled memory conditions, generally associated with a lab.",
      "defensive_takeaways": [
        "Make input length and allocated capacity explicit invariants in normalization code.",
        "Prefer capacity-aware storage operations and safe local regression coverage.",
        "Separate a controlled demonstration from deployment-wide impact claims."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Wiz / ZeroDay.cloud",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "competition-results",
        "evidence_quote": "$30,000 awarded",
        "evidence_location": "MariaDB: Team Xint Code entry in the organizer's Day 2 results",
        "usd_equivalent": null,
        "notes": "One entry award, excluding the team’s other database entries. The results use $; USD denomination is contextualized by the organizer’s current rules, which concern 2026 rather than an archived 2025 rules snapshot. No conversion or cash-settlement claim is made."
      },
      "dates": {
        "published": {
          "value": "2026-05-04",
          "precision": "day",
          "basis": "inferred",
          "source_id": "researcher-report",
          "note": "Displayed May 4; year inferred from the completed 2026 remediation timeline."
        },
        "public_disclosure": {
          "value": "2025-12-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-tracker",
          "note": "Public competition demonstration. Subsequent CVE/advisory publication and full technical article are separate events."
        },
        "reported": {
          "value": "2025-12-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-report",
          "note": "Researcher timeline explicitly dates the report and vendor acknowledgement."
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": "2026-02-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-release",
          "note": "Vendor patch release, not proof of deployment by every customer."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2025-12-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Dated organizer recap announces the exact entry award; decision and transfer dates remain unknown."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "researcher-report",
          "url": "https://www.zeroday.cloud/blog/mariadb-cve-2026-32710-deep-dive",
          "title": "CVE-2026-32710: MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE",
          "type": "researcher",
          "author": "Team Xint Code / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "competition-results",
          "url": "https://www.wiz.io/blog/wiz-zeroday-cloud-hacking-competition-behind-the-scenes",
          "title": "ZeroDay.cloud 2025 individual competition results",
          "type": "competition_organizer",
          "author": "Nir Ohfeld / Wiz Research",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "reward",
            "dates"
          ]
        },
        {
          "id": "competition-tracker",
          "url": "https://www.zeroday.cloud/vulnerability-tracker",
          "title": "ZeroDay.cloud vulnerability tracker",
          "type": "competition_organizer",
          "author": "Wiz / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "dates",
            "cve"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.zeroday.cloud/rules",
          "title": "ZeroDay.cloud current rules: US-dollar denomination",
          "type": "competition_organizer",
          "author": "Wiz",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "vendor-advisory",
          "url": "https://github.com/MariaDB/server/security/advisories/GHSA-4rj5-2227-9wgc",
          "title": "MariaDB heap-based buffer overflow in JSON_SCHEMA_VALID",
          "type": "vendor",
          "author": "MariaDB",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-cve",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/32xxx/CVE-2026-32710.json",
          "title": "CVE-2026-32710 CNA record",
          "type": "vendor",
          "author": "GitHub CNA, MariaDB advisory / CVE Program",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "dates",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-release",
          "url": "https://mariadb.com/docs/release-notes/community-server/11.4/11.4.10",
          "title": "MariaDB 11.4.10 release notes",
          "type": "vendor",
          "author": "MariaDB",
          "retrieved_at": "2026-10-02T18:12:00Z",
          "supports": [
            "dates",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "researcher-report",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T18:12:00Z",
        "method": "Read the named researcher report, organizer CVE tracker and per-entry award result; cross-checked vendor advisories and CNA records. Currency context is explicitly distinguished from award evidence. No vulnerability testing performed.",
        "limitations": [
          "Vendor CVE wording conditions code execution on tight memory control generally obtainable in a lab; do not infer reliable production-wide compromise.",
          "Vendor advisory also lists patched 12.2.2, beyond the two release series emphasized in the research article. The February 4 fix date refers to the reviewed 11.4.10 release.",
          "The article shows May 4 without a year; 2026 is inferred from its explicitly dated remediation timeline.",
          "Exact award decision and funds-transfer dates are not reported; December 16 is the dated organizer announcement.",
          "Current rules establish program US-dollar notation but are not an archived snapshot of the 2025 rules."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-support-api-authorization-2026",
      "title": "Google support API exposed customer and agent data",
      "organization": "Google",
      "product": "Google Real-time Support API",
      "researchers": [
        "Michael Dalton"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "Ordinary authenticated customers could read internal support activity; the researcher reports a USD 14,337 award.",
      "root_cause": "Customer authentication did not enforce the boundary around internal support-wide information. The researcher contrasted denied resource-specific operations with an accessible aggregate operation. This supports an authorization gap; middleware behavior and the intended management use remain hypotheses, not confirmed implementation details.",
      "impact": "Observed disclosures linked customer names or phone numbers with cases and agents, including agent activity. Phishing and harassment were potential consequences. Millions of affected records were estimated; conversation contents and call manipulation were not demonstrated.",
      "defensive_takeaways": [
        "Editorial lesson: treat aggregate views as separately privileged resources; successful authentication is not evidence of permission to observe other users.",
        "Editorial lesson: reducing identifiable details limits the harm when a support-data boundary fails. The source does not document the deployed authorization repair."
      ],
      "reward": {
        "amount": 14337,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Google",
        "evidence_level": "researcher_reported_with_vendor_quote",
        "source_id": "primary",
        "evidence_quote": "Google VRP panel has decided to issue a reward of $14337.00 USD for your report.",
        "evidence_location": "Timeline, June 10, 2025",
        "usd_equivalent": null,
        "notes": "Single report award includes a USD 1,000 report-quality bonus; no settlement date is given."
      },
      "dates": {
        "published": {
          "value": "2026-03-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": "2026-03-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "reported": {
          "value": "2025-06-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2025-06-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The source records closure as fixed on November 12, 2025, not a deployment date."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://michaeldalton.au/posts/hacking-google-support",
          "title": "Hacking Google Support: Leaking millions of customer records ($14k bounty)",
          "type": "researcher",
          "author": "Michael Dalton",
          "retrieved_at": "2026-10-03T04:49:20Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T04:49:20Z",
        "method": "Fresh-read the primary disclosure and timeline; separated observed disclosure from hypothesized reach. No target testing or reproduction.",
        "limitations": [
          "Researcher-published evidence does not independently establish settlement, total affected population, backend implementation or deployed repair.",
          "The prerequisite was an ordinary signed-in account; describing the exposure as unauthenticated would erase that requirement."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "google-chrome-v8-type-consistency-2025",
      "title": "V8 optimized object handling retained invalid type assumptions",
      "organization": "Google",
      "product": "Chrome / V8",
      "researchers": [
        "Man Yue Mo (GitHub Security Lab)"
      ],
      "cve_ids": [
        "CVE-2025-12428"
      ],
      "cwe_mappings": [],
      "category_id": "memory-safety",
      "secondary_category_ids": [
        "client-security"
      ],
      "skillset_ids": [
        "memory-safety-review",
        "browser-isolation-review",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "summary": "One V8 type-consistency report earned a USD 50,000 award.",
      "root_cause": "Optimized object handling could retain invalid type assumptions, producing a type-consistency failure.",
      "impact": "Memory read/write was possible; broader code execution required an additional boundary failure.",
      "defensive_takeaways": [
        "Optimized execution must invalidate cached assumptions when object state changes and handle all supported object families consistently.",
        "Distinguish issue-status fixes from stable-release availability."
      ],
      "reward": {
        "amount": 50000,
        "currency": "USD",
        "scope": "single_vulnerability",
        "type": "bug_bounty",
        "awarding_organization": "Google / Chrome VRP",
        "status": "awarded",
        "evidence_level": "vendor_confirmed",
        "source_id": "vendor-report",
        "evidence_quote": "award you $50000.00 for this report",
        "evidence_location": "Public Chromium issue comment #13.",
        "usd_equivalent": null,
        "notes": "Case notices use $; USD is contextual from the official Chromium program source. No currency conversion or cash-receipt claim."
      },
      "dates": {
        "published": {
          "value": "2026-03-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-advisory",
          "note": "Detailed researcher advisory; public issue access opened January 13, 2026, after the October 2025 vendor notice."
        },
        "public_disclosure": {
          "value": "2025-10-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Vendor release disclosure; full issue access was enabled later."
        },
        "reported": {
          "value": "2025-09-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": null
        },
        "awarded": {
          "value": "2025-10-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": null
        },
        "fixed": {
          "value": "2025-10-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Documented stable release; issue was marked Fixed 2025-10-06. Backport availability may differ."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2025-10-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Per-issue reward listed in the public release notice."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "vendor-report",
          "url": "https://issues.chromium.org/issues/447613211",
          "title": "Chromium issue 447613211",
          "type": "vendor",
          "author": "Google Chromium security team",
          "retrieved_at": "2026-10-02T16:08:00Z",
          "supports": [
            "reward",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html?hl=fr",
          "title": "Chrome Stable Channel Update for Desktop, 2025-10-28",
          "type": "vendor",
          "author": "Google Chrome team",
          "retrieved_at": "2026-10-02T16:08:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "cve",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://blog.chromium.org/2013/08/security-rewards-at-google-two.html",
          "title": "Security rewards at Google: Two MEEELLION Dollars Later",
          "type": "vendor",
          "author": "Chromium team",
          "retrieved_at": "2026-10-02T16:08:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "researcher-advisory",
          "url": "https://securitylab.github.com/advisories/GHSL-2025-114_Chromium/",
          "title": "GHSL-2025-114: Chromium V8 advisory",
          "type": "researcher",
          "author": "Man Yue Mo / GitHub Security Lab",
          "retrieved_at": "2026-10-02T16:08:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "cve",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "researcher-advisory",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T16:08:00Z",
        "method": "Public Chromium issue award/date metadata read in the cloud browser; official release corroborates exact per-issue total and CVE. Researcher advisory independently reviewed.",
        "limitations": [
          "Case notices use dollar notation; USD denomination relies on official Chromium program context.",
          "Award decisions are established; payment completion is not.",
          "Fixed status and publicly available stable release are separate dates.",
          "Release list revised November 17, 2025; it identifies the newly added entries separately as CVE-2025-13226 through 13230. This record retains the October 28 release disclosure."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-gemini-enterprise-connected-content-memory-integrity-2026",
      "title": "Gemini Enterprise connected-content trust failure allowed persistent-memory modification",
      "organization": "Google",
      "product": "Gemini Enterprise Jira integration",
      "researchers": [
        "Behi"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "ai-security",
      "secondary_category_ids": [
        "authorization"
      ],
      "skillset_ids": [
        "ai-authority-boundaries",
        "integration-threat-modeling",
        "authorization-modeling",
        "untrusted-input-handling",
        "defensive-evidence-writing"
      ],
      "summary": "A researcher reports a $15,000 Google bounty for a Gemini Enterprise integration issue affecting persistent assistant memory.",
      "root_cause": "The researcher compared user-confirmed actions with persistent memory changes. Retrieved collaboration content could influence an operation that changed saved state without equivalent confirmation. The failed boundary was between permission to read connected data and authority to mutate the user’s lasting assistant state.",
      "impact": "In a two-account setup, the researcher confirmed deletion of the test recipient’s saved memories. The scenario required shared-project content access and user-initiated retrieval. Broader cross-tenant access, mailbox compromise and lasting changes to every future response were not demonstrated.",
      "defensive_takeaways": [
        "Model persistent memory as a security-sensitive write operation with its own authorization decision.",
        "Preserve provenance when retrieved content passes between a connector, model and state-changing component.",
        "Require a trusted authorization signal for each write; permission to summarize content should not imply permission to alter saved preferences.",
        "Separate observed state changes from speculative downstream behavior in impact reports; the public article does not establish the vendor’s remediation design."
      ],
      "reward": {
        "amount": 15000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "Google",
        "status": "paid",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "Google paid me $15,000 for this Prompt Injection bug.",
        "evidence_location": "Article title",
        "usd_equivalent": null,
        "notes": "The researcher reports being paid $15,000 for this distinct finding; do not combine the separate $1,337 example. Exact award/settlement date is unknown. Dollar-denominated Google bounty; USD normalization. The individual write-up uses the $ symbol rather than spelling out USD."
      },
      "dates": {
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "published": {
          "value": "2026-03-12",
          "precision": "day",
          "basis": "inferred",
          "source_id": "primary",
          "note": "DEV article March 12, 2026; the researcher's Reddit write-up is dated March 9, 2026. Original X post is linked but its exact date was not independently established. No exact report, award, or fix dates were found."
        },
        "public_disclosure": {
          "value": "2026-03-09",
          "precision": "day",
          "basis": "explicit",
          "source_id": "source-2",
          "note": "Earlier researcher publication on Reddit; linked original X post might be earlier."
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://dev.to/behi_sec/google-paid-me-15000-for-this-prompt-injection-bug-5fn6",
          "title": "Google paid me $15,000 for this Prompt Injection bug.",
          "type": "researcher",
          "author": "Behi",
          "retrieved_at": "2026-10-02T20:20:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "source-2",
          "url": "https://www.reddit.com/r/bugbounty/comments/1row41z/google_paid_me_15000_for_this_prompt_injection_bug/",
          "title": "Supporting primary disclosure source",
          "type": "researcher",
          "author": "Behi",
          "retrieved_at": "2026-10-02T03:54:00Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T20:20:00Z",
        "method": "Re-read the researcher’s primary article, preserving its individual payout attribution and distinguishing the observed test-account memory deletion from broader inferred impact.",
        "limitations": [
          "No vendor-hosted confirmation of this individual payout found",
          "Do not confuse this finding with the separate $1,337 memory issue mentioned in the introduction",
          "Remediation date, exact patch design and current status are not independently established",
          "The reported demonstration used two researcher-controlled accounts; it does not establish actual customer compromise"
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "angular-ci-cache-trust-2026",
      "title": "Angular automation trust and cache isolation weakness",
      "organization": "Google",
      "product": "Angular development and release infrastructure",
      "researchers": [
        "Adnan Khan"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "supply-chain",
      "secondary_category_ids": [
        "injection",
        "authorization"
      ],
      "skillset_ids": [
        "pipeline-trust-modeling",
        "cache-artifact-isolation",
        "machine-identity-governance",
        "secrets-containment",
        "approval-state-integrity",
        "defensive-evidence-writing"
      ],
      "summary": "A Google-rewarded report connected an adjacent CI misconfiguration with insufficient separation of automation trust, creating a potential Angular supply-chain impact.",
      "root_cause": "Untrusted workflow input and shared build state crossed trust boundaries; bot-specific approval assumptions increased the potential consequence.",
      "impact": "The researcher demonstrated credential exposure and modeled the remaining path to repository control without executing the final supply-chain modification. Google classified the report as a flagship supply-chain compromise.",
      "defensive_takeaways": [
        "Separate caches and artifacts according to trust level.",
        "Apply consistent review invalidation and least-privilege rules to automated identities.",
        "Record which impacts were directly demonstrated versus established through design evidence."
      ],
      "reward": {
        "amount": 31337,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "evidence_level": "researcher_reported_with_vendor_quote",
        "source_id": "primary",
        "evidence_quote": "decided to issue a reward of $31337.00 for your report",
        "evidence_location": "Success section, quoted Google award email",
        "usd_equivalent": null,
        "notes": "A Google award email is quoted within the researcher publication; it is not an independently accessed vendor award record. The quote uses only $. USD is a contextual currency inference from the official OSS VRP rules (currency-context), whose Reward amounts section explicitly denominates discretionary bonuses in USD. Those living rules were reviewed on October 3, 2026, after the January 28 award; their wording at award time was not established. They are denomination context only, not proof of this individual award or settlement. No bonus is established or added.",
        "type": "bug_bounty",
        "awarding_organization": "Google"
      },
      "dates": {
        "published": {
          "value": "2026-03-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": "2026-03-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Publication of this write-up; earliest disclosure elsewhere was not independently established."
        },
        "reported": {
          "value": "2025-12-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2026-01-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": "2025-12-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Researcher timeline says the report was marked fixed on this date; deployment timing and patch effectiveness were not independently verified."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Cash settlement date not independently established."
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": "2025-12-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Researcher timeline records disabling the workflow as mitigation."
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://adnanthekhan.com/posts/angular-compromise-through-dev-infra/",
          "title": "Turning Almost Nothing into a Supply Chain Compromise of Angular with GitHub Actions Cache Poisoning",
          "type": "researcher",
          "author": "Adnan Khan",
          "retrieved_at": "2026-10-03T19:52:01Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules#reward-amounts",
          "title": "Google Open Source Software Vulnerability Reward Program Rules — Reward amounts",
          "type": "vendor",
          "author": "Google",
          "retrieved_at": "2026-10-03T19:53:20Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T19:54:00Z",
        "method": "Primary researcher award and timeline reread; official OSS VRP rules read for contextual denomination only. Award distinguished from program maximums and aggregate earnings. No vulnerability testing performed.",
        "limitations": [
          "The reward is an actual award reported in a primary researcher account; payment settlement was not independently audited.",
          "USD is contextually inferred from later program-level denomination wording, not explicitly stated in the quoted individual award. No conflicting denomination was identified in the reviewed sources."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "postgresql-extension-input-type-validation-2026",
      "title": "PostgreSQL extension estimator trusted an unchecked input type",
      "organization": "PostgreSQL",
      "product": "PostgreSQL intarray extension",
      "researchers": [
        "Daniel Firer"
      ],
      "cve_ids": [
        "CVE-2026-2004"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-1287",
          "basis": "source_explicit",
          "source_id": "vendor-cve",
          "note": "The PostgreSQL CNA explicitly classifies improper validation of the specified input type."
        }
      ],
      "category_id": "memory-safety",
      "secondary_category_ids": [
        "cloud-security"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "memory-safety-review",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "summary": "Wiz confirms a USD 30,000 competition award for Daniel Firer’s PostgreSQL entry, uniquely mapped by the organizer to CVE-2026-2004.",
      "root_cause": "The extension’s selectivity estimator accepted input without checking that its type matched the routine’s expectations. This broke the contract between database objects an authorized user could create and native extension code running with database-process authority.",
      "impact": "The vendor confirms possible code execution as the database operating-system account. A user needed permission to install the vulnerable extension, or an existing installation plus object-creation permission. The public sources do not establish a universal unauthenticated or cross-tenant compromise.",
      "defensive_takeaways": [
        "Validate input types at extension boundaries before applying native-code assumptions.",
        "Review extension installation and object-creation privileges together; either permission in isolation can hide the relevant trust boundary.",
        "Verify the vendor’s fixed releases and keep the database process identity limited to necessary resources."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Wiz / ZeroDay.cloud",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "competition-results",
        "evidence_quote": "$30,000 awarded",
        "evidence_location": "PostgreSQL: Daniel Firer entry in the organizer’s Day 1 results",
        "usd_equivalent": null,
        "notes": "One individually identified competition entry. The organizer uses $; its current rules establish US-dollar notation but concern 2026, not an archived 2025 rules snapshot. Exact award decision and cash settlement are unknown."
      },
      "dates": {
        "published": {
          "value": "2026-02-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-cve",
          "note": "Publication of the vendor CNA record; no separate detailed researcher article was established."
        },
        "public_disclosure": {
          "value": "2025-12-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-tracker",
          "note": "Public competition demonstration; separate from later vendor advisory and technical publication."
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Exact initial report to the vendor is not stated; the tracker dates the competition entry, not vendor receipt."
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": "2026-02-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-advisory",
          "note": "Vendor release date for PostgreSQL 18.2, 17.8, 16.12, 15.16 and 14.21; individual deployment dates remain unknown."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2025-12-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Organizer recap confirms the per-entry award; decision and payment dates remain unknown."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "competition-results",
          "url": "https://www.wiz.io/blog/wiz-zeroday-cloud-hacking-competition-behind-the-scenes",
          "title": "ZeroDay.cloud 2025 individual competition results",
          "type": "competition_organizer",
          "author": "Nir Ohfeld / Wiz Research",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "reward",
            "dates"
          ]
        },
        {
          "id": "competition-tracker",
          "url": "https://www.zeroday.cloud/vulnerability-tracker",
          "title": "ZeroDay.cloud vulnerability tracker",
          "type": "competition_organizer",
          "author": "Wiz / ZeroDay.cloud",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "dates",
            "cve"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.zeroday.cloud/rules",
          "title": "ZeroDay.cloud current rules: US-dollar denomination",
          "type": "competition_organizer",
          "author": "Wiz",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "vendor-advisory",
          "url": "https://www.postgresql.org/support/security/CVE-2026-2004/",
          "title": "PostgreSQL CVE-2026-2004 security advisory",
          "type": "vendor",
          "author": "PostgreSQL",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-cve",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/2xxx/CVE-2026-2004.json",
          "title": "CVE-2026-2004 PostgreSQL CNA record",
          "type": "vendor",
          "author": "PostgreSQL CNA / CVE Program",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "vendor-advisory",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T19:21:00Z",
        "method": "Matched the organizer’s named PostgreSQL award to the tracker’s exact CVE, then checked the vendor advisory and CNA prerequisites. Summary remains within the published technical evidence.",
        "limitations": [
          "The technical basis is the vendor advisory, not a detailed researcher walkthrough; discovery reasoning beyond that evidence is unknown.",
          "The December competition demonstration, February advisory publication, award announcement and unknown payment date are distinct events.",
          "Current rules provide explicit USD context but are not the archived 2025 rules."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "google-chrome-v8-initialization-checks-2025",
      "title": "V8 control-flow analysis omitted required initialization checks",
      "organization": "Google",
      "product": "Chrome / V8",
      "researchers": [
        "Aorui Zhang"
      ],
      "cve_ids": [
        "CVE-2025-12429"
      ],
      "cwe_mappings": [],
      "category_id": "memory-safety",
      "secondary_category_ids": [
        "client-security"
      ],
      "skillset_ids": [
        "memory-safety-review",
        "browser-isolation-review",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "summary": "A distinct V8 initialization-check report received a vendor-confirmed USD 50,000 award.",
      "root_cause": "Control-flow analysis treated an initialization safety check as redundant without preserving its guarantee across every incoming path.",
      "impact": "The report demonstrated sandboxed renderer memory corruption. A sandbox escape or full-machine compromise is not established.",
      "defensive_takeaways": [
        "Check-removal optimizations must preserve initialization guarantees across all control-flow paths.",
        "Separate a compiler fix, stable-release availability and public report access in remediation records."
      ],
      "reward": {
        "amount": 50000,
        "currency": "USD",
        "scope": "single_vulnerability",
        "type": "bug_bounty",
        "awarding_organization": "Google / Chrome VRP",
        "status": "awarded",
        "evidence_level": "vendor_confirmed",
        "source_id": "vendor-report",
        "evidence_quote": "Panel has decided to award you $50000.00 for this report.",
        "evidence_location": "Public Chromium issue comment #17.",
        "usd_equivalent": null,
        "notes": "Panel decision and tracker reward metadata identify one report. Dollar notation uses official Chromium USD context. Cash receipt is unverified."
      },
      "dates": {
        "published": {
          "value": "2026-01-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": "Comment #24 records removal of issue access restrictions."
        },
        "public_disclosure": {
          "value": "2025-10-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Vendor advisory preceded full issue access."
        },
        "reported": {
          "value": "2025-10-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": null
        },
        "awarded": {
          "value": "2025-10-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": null
        },
        "fixed": {
          "value": "2025-10-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Stable release announced staged rollout; main fix recorded October 10 and Fixed status October 15."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2025-10-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Listed in the dated release notice; no original-page snapshot reviewed."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "vendor-report",
          "url": "https://issues.chromium.org/issues/450618029",
          "title": "Chromium issue 450618029",
          "type": "vendor",
          "author": "Google Chromium security team",
          "retrieved_at": "2026-10-02T16:21:50Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "release",
          "url": "https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html?hl=fr",
          "title": "Chrome Stable Channel Update for Desktop, 2025-10-28",
          "type": "vendor",
          "author": "Google Chrome team",
          "retrieved_at": "2026-10-02T16:21:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "cve",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://blog.chromium.org/2013/08/security-rewards-at-google-two.html",
          "title": "Security rewards at Google: Two MEEELLION Dollars Later",
          "type": "vendor",
          "author": "Chromium team",
          "retrieved_at": "2026-10-02T16:08:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "vendor-report",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T16:21:50Z",
        "method": "Read the public rendered Chromium issue and official release; cross-checked panel decision, reward metadata and distinct CVE.",
        "limitations": [
          "Payment completion is unverified; USD relies on official program context.",
          "Issue dates follow displayed calendar dates; timestamp timezone was not established.",
          "Release page was corrected November 17 to add other CVEs. This entry remains in the original main list."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "microsoft-kestrel-http-framing-consistency-2025",
      "title": "Kestrel HTTP framing differed across proxy and application boundaries",
      "organization": "Microsoft",
      "product": "ASP.NET Core / Kestrel",
      "researchers": [
        "Siddhant Kalgutkar (Praetorian)"
      ],
      "cve_ids": [
        "CVE-2025-55315"
      ],
      "cwe_mappings": [],
      "category_id": "injection",
      "secondary_category_ids": [
        "authorization"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "untrusted-input-handling",
        "integration-threat-modeling",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "summary": "A Kestrel request-framing report earned a researcher-reported USD 10,000 award.",
      "root_cause": "Permissive HTTP framing validation could disagree with an upstream parser about message boundaries.",
      "impact": "Security controls could be bypassed in affected deployments. Consequences depended on the complete proxy/application architecture, not merely the presence of Kestrel.",
      "defensive_takeaways": [
        "Define consistent message-boundary contracts across intermediaries and application servers; reject ambiguous framing.",
        "Verify deployed runtimes and self-contained applications receive the applicable vendor updates."
      ],
      "reward": {
        "amount": 10000,
        "currency": "USD",
        "scope": "single_vulnerability",
        "type": "bug_bounty",
        "awarding_organization": "Microsoft / .NET Bounty Program",
        "status": "awarded",
        "evidence_level": "researcher_reported",
        "source_id": "researcher-writeup",
        "evidence_quote": "Bounty Awarded: July 21, 2025 ($10,000)",
        "evidence_location": "Timeline section.",
        "usd_equivalent": null,
        "notes": "Exact award comes from the researcher. The July 31, 2025 official program announcement supplies USD context only; its later award-table changes do not establish this amount. Payment completion is unverified."
      },
      "dates": {
        "published": {
          "value": "2025-11-07",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Detailed article date; vendor disclosure preceded it."
        },
        "public_disclosure": {
          "value": "2025-10-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-advisory",
          "note": null
        },
        "reported": {
          "value": "2025-06-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": "2025-07-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "fixed": {
          "value": "2025-10-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Public patch release; vendor advisory independently identifies patched versions."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "First public award-announcement date is not established."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://www.praetorian.com/blog/how-i-found-the-worst-asp-net-vulnerability-a-10k-bug-cve-2025-55315/",
          "title": "ASP.NET Core CVE-2025-55315 disclosure and award timeline",
          "type": "researcher",
          "author": "Siddhant Kalgutkar / Praetorian",
          "retrieved_at": "2026-10-02T16:20:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-advisory",
          "url": "https://github.com/dotnet/aspnetcore/security/advisories/GHSA-5rrx-jjjq-q2r5",
          "title": "Microsoft Security Advisory CVE-2025-55315",
          "type": "vendor",
          "author": "Microsoft .NET security team",
          "retrieved_at": "2026-10-02T16:20:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.microsoft.com/en-us/msrc/blog/2025/07/net-bounty-program-now-offers-up-to-40000-in-awards",
          "title": ".NET Bounty Program update, July 31, 2025",
          "type": "vendor",
          "author": "Madeline Eckert and Barry Dorrans / Microsoft",
          "retrieved_at": "2026-10-02T16:21:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T16:21:00Z",
        "method": "Read the primary researcher article and timeline, vendor advisory and July 2025 official USD-denominated program announcement.",
        "limitations": [
          "The award and its date are researcher-reported, not independently vendor-confirmed.",
          "Impact varies with deployment architecture; generic consequences are not evidence of actual victim compromise.",
          "Dollar notation is interpreted through official program currency context; no conversion is used."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-gemini-colab-rendering-boundary-2025",
      "title": "Gemini-to-Colab rendering boundary exposed Workspace data",
      "organization": "Google",
      "product": "Gemini Export to Colab",
      "researchers": [
        "Valentino Massaro"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "ai-security",
      "secondary_category_ids": [
        "injection",
        "client-security"
      ],
      "skillset_ids": [
        "ai-authority-boundaries",
        "integration-threat-modeling",
        "secure-parser-review",
        "untrusted-input-handling"
      ],
      "summary": "Google awarded USD 20,000 for the Colab-export finding in a multi-finding research article.",
      "root_cause": "Content considered inert by Gemini could acquire active rendering behavior in Colab. The integration did not preserve the same sanitization contract across that boundary.",
      "impact": "The researcher reports confirming Workspace-data disclosure after a user exported content to Colab. The scenario depended on Gemini encountering untrusted content and having access to connected data. Suggested delivery through poisoned training data or embeddings was not separately demonstrated.",
      "defensive_takeaways": [
        "Maintain consistent content-handling contracts across integration boundaries.",
        "Enforce output destinations independently from generated or retrieved text.",
        "Treat export as a new interpretation boundary; validate the destination representation rather than assuming upstream sanitization remains effective."
      ],
      "reward": {
        "amount": 20000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Google",
        "evidence_level": "researcher_reported_with_vendor_quote",
        "source_id": "primary",
        "evidence_quote": "decided to issue a reward of $20000.00 for your report",
        "evidence_location": "Colaboratory markdown sanitizer bypass, May 20 timeline",
        "usd_equivalent": null,
        "notes": "This amount belongs to the Colab finding; a separate Gemini-only finding was marked duplicate."
      },
      "dates": {
        "published": {
          "value": "2025-11",
          "precision": "month",
          "basis": "explicit",
          "source_id": "publication-index",
          "note": "Author homepage supplies November 2025; exact publication day is not established."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2025-04-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2025-05-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://buganizer.cc/hacking-gemini-a-multi-layered-approach-md/",
          "title": "Hacking Gemini: A Multi-Layered Approach",
          "type": "researcher",
          "author": "Valentino Massaro",
          "retrieved_at": "2026-10-03T05:19:42Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "publication-index",
          "url": "https://buganizer.cc/",
          "title": "Valentino’s issue tracker",
          "type": "researcher",
          "author": "Valentino Massaro",
          "retrieved_at": "2026-10-03T05:19:42Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T05:19:42Z",
        "method": "Fresh-read the researcher article and publication index; separated prerequisites and observed disclosure from suggested delivery methods. No testing performed.",
        "limitations": [
          "Award correspondence is researcher-published; settlement is not independently verified.",
          "The separate Gemini-only finding was a duplicate, not another award.",
          "No exact publication day, fix date or vendor patch design is established."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "github-ruby-dependency-confusion-2025",
      "title": "GitHub package-source trust allowed dependency confusion",
      "organization": "GitHub",
      "product": "GitHub build and development services",
      "researchers": [
        "Furbreeze"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "supply-chain",
      "secondary_category_ids": [
        "injection"
      ],
      "skillset_ids": [
        "dependency-provenance",
        "pipeline-trust-modeling",
        "secrets-containment",
        "defensive-evidence-writing"
      ],
      "summary": "A researcher reported one dependency-confusion finding affecting GitHub build and development services and a $20,000 award.",
      "root_cause": "Dependency resolution crossed the intended boundary between internal Ruby packages and a public package source.",
      "impact": "The researcher observed code execution across multiple service contexts. The disclosed account does not establish a broader compromise beyond those observations.",
      "defensive_takeaways": [
        "Define explicit package sources and reserve internal namespaces where applicable.",
        "Treat build and developer environments as separate trust zones and minimize their credentials."
      ],
      "reward": {
        "amount": 20000,
        "currency": "USD",
        "scope": "single_report",
        "status": "paid",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "Issue closed, bounty of $20k rewarded. […] The bounty they paid me",
        "evidence_location": "Timeline, October 21 entry (award); numbered facts list, item 3 (payment)",
        "usd_equivalent": null,
        "notes": "The researcher states this was a critical report and that the bounty was paid; no separate payment date or public HackerOne report is supplied.",
        "type": "bug_bounty",
        "awarding_organization": "GitHub"
      },
      "dates": {
        "published": {
          "value": "2025-10-28",
          "precision": "day",
          "basis": "url_date",
          "source_id": "primary",
          "note": "Date encoded in the researcher publication permalink; earliest disclosure elsewhere was not independently established."
        },
        "public_disclosure": {
          "value": "2025-10-28",
          "precision": "day",
          "basis": "url_date",
          "source_id": "primary",
          "note": "Date encoded in the researcher publication permalink; earliest disclosure elsewhere was not independently established."
        },
        "reported": {
          "value": "2025-09-01",
          "precision": "day",
          "basis": "inferred",
          "source_id": "primary",
          "note": "The timeline supplies September 1; year is inferred from the 2025 publication context."
        },
        "awarded": {
          "value": "2025-10-21",
          "precision": "day",
          "basis": "inferred",
          "source_id": "primary",
          "note": "The timeline supplies October 21; year is inferred from the 2025 publication context."
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Cash settlement date not independently established."
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://furbreeze.github.io/2025/10/28/vibecoding-my-way-to-a-crit-on-github.html",
          "title": "Vibecoding my way to a crit on Github",
          "type": "researcher",
          "author": "Furbreeze",
          "retrieved_at": "2026-10-04T11:40:43Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-04T11:43:25Z",
        "method": "Primary public source read; award distinguished from program maximums and aggregate earnings. No vulnerability testing performed.",
        "limitations": [
          "The reward is an actual award reported in a primary researcher account; payment settlement was not independently audited."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "redis-lua-object-lifetime-isolation-2025",
      "title": "Redis Lua object lifetime failure crossed the scripting boundary",
      "organization": "Redis",
      "product": "Redis with Lua scripting",
      "researchers": [
        "Benny Isaacs",
        "Nir Brakha",
        "Sagi Tzadik"
      ],
      "cve_ids": [
        "CVE-2025-49844"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-416",
          "basis": "source_explicit",
          "source_id": "vendor-advisory",
          "note": "Explicit classification in the vendor security advisory."
        }
      ],
      "category_id": "memory-safety",
      "secondary_category_ids": [
        "cloud-security"
      ],
      "skillset_ids": [
        "memory-safety-review",
        "integration-threat-modeling",
        "authorization-modeling",
        "patch-verification"
      ],
      "summary": "ZDI awarded Wiz researchers USD 40,000 for this single Pwn2Own Berlin 2025 entry.",
      "root_cause": "Lua garbage collection could leave an object referenced after its memory was freed, undermining the interpreter’s memory-safety assumptions.",
      "impact": "The vendor confirms possible native code execution by an authenticated user able to run Lua scripts. This crosses the scripting boundary; host impact remains dependent on process privileges and deployment isolation.",
      "defensive_takeaways": [
        "Review object-lifetime invariants across embedded interpreters and native components.",
        "Grant scripting access only where needed and retain least-privilege service execution.",
        "Check corrected vendor release guidance instead of relying on an early fixed-version summary."
      ],
      "reward": {
        "amount": 40000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Trend Micro Zero Day Initiative / Pwn2Own Berlin",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "competition-results",
        "evidence_quote": "They earn $40,000",
        "evidence_location": "Named Wiz researchers’ entry in the organizer’s dated daily results",
        "usd_equivalent": null,
        "notes": "One competition-entry award, not the researchers’ event total. Official rules specify US currency; recipient allocation and actual cash settlement are unverified."
      },
      "dates": {
        "published": {
          "value": "2025-10-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-report",
          "note": "Primary research article publication; earlier competition results are separately dated."
        },
        "public_disclosure": {
          "value": "2025-05-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Public demonstration and result; vendor technical advisory followed later."
        },
        "reported": {
          "value": "2025-05-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-report",
          "note": "Researcher timeline explicitly ties this CVE to its May 16 Pwn2Own report."
        },
        "awarded": {
          "value": "2025-05-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Award announced for the named individual entry."
        },
        "fixed": {
          "value": "2025-10-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-report",
          "note": "Researcher article states that Redis released its advisory and patched version on this date. This is not a universal customer-deployment date; later vendor corrections affected some Redis Software fixed-version labels."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2025-05-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": true,
        "basis": "published",
        "note": null
      },
      "sources": [
        {
          "id": "researcher-report",
          "url": "https://www.wiz.io/blog/wiz-research-redis-rce-cve-2025-49844",
          "title": "RediShell: Redis CVE-2025-49844",
          "type": "researcher",
          "author": "Benny Isaacs and Nir Brakha / Wiz Research",
          "retrieved_at": "2026-10-02T17:39:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "competition-results",
          "url": "https://www.zerodayinitiative.com/blog/2025/5/16/pwn2own-berlin-2025-day-two-results",
          "title": "Pwn2Own Berlin 2025 daily results",
          "type": "competition_organizer",
          "author": "Dustin Childs / Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:39:00Z",
          "supports": [
            "reward",
            "dates",
            "impact"
          ]
        },
        {
          "id": "competition-rules",
          "url": "https://www.zerodayinitiative.com/Pwn2OwnBerlin2025Rules.html",
          "title": "Pwn2Own Berlin 2025 rules",
          "type": "competition_organizer",
          "author": "Trend Micro Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:39:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "vendor-advisory",
          "url": "https://github.com/redis/redis/security/advisories/GHSA-4789-qfc9-5f9q",
          "title": "Redis Lua Use-After-Free security advisory",
          "type": "vendor",
          "author": "Redis maintainers",
          "retrieved_at": "2026-10-02T17:39:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-guidance",
          "url": "https://redis.io/blog/security-advisory-cve-2025-49844/",
          "title": "Redis CVE-2025-49844 remediation guidance and corrections",
          "type": "vendor",
          "author": "Riaz Lakhani / Redis",
          "retrieved_at": "2026-10-02T17:39:00Z",
          "supports": [
            "dates",
            "impact",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "researcher-report",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T17:39:00Z",
        "method": "Read the researcher’s explicit CVE-to-Pwn2Own submission timeline and matched its date, product and named researchers to the organizer’s individual-entry award; corroborated CVE and scope with vendor guidance. Official rules establish USD denomination.",
        "limitations": [
          "Single competition-entry award; individual recipient splits and cash-transfer date are unknown.",
          "The October 6 article is the primary research publication; May demonstration and October 3 vendor advisory are distinct events.",
          "Vendor Redis Software release labels were corrected on October 27 and October 30, 2025; this record does not assume every product variant was fixed in its originally listed version."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "github-cross-repository-comparison-authorization-2025",
      "title": "GitHub comparison output lacked source-repository authorization",
      "organization": "GitHub",
      "product": "GitHub Enterprise Server",
      "researchers": [
        "furbreeze"
      ],
      "cve_ids": [
        "CVE-2025-8447"
      ],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "defensive-evidence-writing",
        "patch-verification"
      ],
      "summary": "GitHub awarded USD 10,000 for a GHES comparison feature that exposed limited code across repository permission boundaries (vendor-report).",
      "root_cause": "GitHub identifies improper access control in cross-repository comparison (vendor-report; vendor-release). Access to one repository did not establish permission to disclose content from another contributing repository. The vendor describes prerequisites of existing repository access and prior knowledge of private-repository references; this was not described as unrestricted anonymous browsing. The conceptual failure is authorizing a derived view without preserving every source repository’s access boundary; implementation-level check placement is not disclosed.",
      "impact": "The vendor confirms limited code disclosure from an otherwise unauthorized repository (vendor-report; vendor-release). The public summary does not establish complete repository extraction, write access, account takeover, or exploitation in the wild; those outcomes must not be inferred from the broader report title.",
      "defensive_takeaways": [
        "Editorial design lesson: authorize every contributing source under the requesting actor before returning a combined or derived view.",
        "Editorial review objective: ensure that permission to access one repository never substitutes for permission to read another repository’s content.",
        "GitHub lists historical fixes in GHES 3.14.17, 3.15.12, 3.16.8 and 3.17.5 (vendor-report). These are historical remediation evidence, not current upgrade recommendations; the 3.17 documentation now marks that release series unsupported (vendor-release)."
      ],
      "reward": {
        "amount": 10000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "GitHub",
        "evidence_level": "vendor_confirmed",
        "source_id": "vendor-report",
        "evidence_quote": "rewarded furbreeze with a $10,000 bounty.",
        "evidence_location": "August 26, 2025 bounty event, activity-36550008.",
        "usd_equivalent": null,
        "notes": "One report award; cash receipt is unverified. USD is inferred from HackerOne’s platform-wide payment policy reviewed in October 2026, later than the August 2025 award; that context does not independently establish settlement."
      },
      "dates": {
        "published": {
          "value": "2025-09-23",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": "Detailed report disclosure event, activity-37054322."
        },
        "public_disclosure": {
          "value": "2025-08-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-release",
          "note": "Vendor advisory in Enterprise Server 3.17.5 release notes preceded the detailed report."
        },
        "reported": {
          "value": "2025-05-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": null
        },
        "awarded": {
          "value": "2025-08-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-report",
          "note": null
        },
        "fixed": {
          "value": "2025-08-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-release",
          "note": "Public GHES 3.17.5 release. Report Resolved status is August 26; GitHub.com deployment timing is not established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical detailed disclosure falls ten days before the preferred publication window."
      },
      "sources": [
        {
          "id": "vendor-report",
          "url": "https://hackerone.com/reports/3124517",
          "title": "GitHub HackerOne report 3124517",
          "type": "vendor",
          "author": "GitHub security team and furbreeze",
          "retrieved_at": "2026-10-03T05:30:46Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-release",
          "url": "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.5",
          "title": "GitHub Enterprise Server 3.17.5 release notes",
          "type": "vendor",
          "author": "GitHub",
          "retrieved_at": "2026-10-03T05:30:46Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.hackerone.com/terms/disclosure-guidelines",
          "title": "Vulnerability Disclosure Standards: Bug Bounty payment denomination",
          "type": "platform",
          "author": "HackerOne",
          "retrieved_at": "2026-10-03T05:30:46Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "vendor-report",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T05:30:46Z",
        "method": "Freshly read public GitHub summary and award/disclosure events in the cloud browser, plus GitHub release notes and HackerOne currency policy through web retrieval. Added bounded conceptual analysis without reproduction or testing.",
        "limitations": [
          "Public report content supplies a vendor summary, not implementation-level patch details or a complete demonstration transcript.",
          "GitHub.com deployment timing and exploitation-in-the-wild status are not established by the reviewed sources.",
          "Release availability, report resolution and detailed publication have different dates.",
          "Cash receipt is unverified; later platform-wide USD policy is contextual denomination evidence."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "hackerone-support-confluence-access-boundary-2025",
      "title": "Support integration exposed internal Confluence documentation",
      "organization": "HackerOne",
      "product": "HackerOne support and internal documentation",
      "researchers": [
        "madara_",
        "red_darkin"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "A support-system misconfiguration allowed external access to internal Confluence documentation, including limited content modification. One report received USD 12,500 split between two researchers.",
      "root_cause": "The vendor attributes the issue to a support-system misconfiguration that allowed support workflows to cross the boundary into internal documentation. The public summary does not reveal the precise configuration, authentication prerequisites or permission-propagation mechanism; an identity-entitlement failure is a defensive interpretation, not a documented implementation detail.",
      "impact": "The vendor confirms access to nonpublic internal documentation and the ability to view and modify limited Confluence content. It does not establish unrestricted administrative control, the volume of material exposed, or broader compromise. The timeline records accepted retesting and Resolved status on June 3, 2025; redacted comment bodies do not reveal the corrective configuration or exact deployment date.",
      "defensive_takeaways": [
        "Editorial lesson: assess whether external support workflows can confer access to employee-only documentation.",
        "Editorial lesson: review integration permissions separately for read and write access; limited modification is distinct from unrestricted control.",
        "Editorial lesson: verify the corrected access boundary after configuration changes without treating a resolution status as evidence of the precise fix."
      ],
      "reward": {
        "amount": 12500,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "HackerOne",
        "status": "awarded",
        "evidence_level": "vendor_confirmed",
        "source_id": "primary",
        "evidence_quote": "rewarded red_darkin with a $5,000 bounty. … rewarded madara_ with a $7,500 bounty.",
        "evidence_location": "Two award events May 30, 2025 at 21:16 UTC; ellipsis joins fragments.",
        "usd_equivalent": null,
        "notes": "Dollar notation appears in the report UI; USD denomination is contextual from HackerOne’s disclosure policy. Award events do not establish cash receipt. One-report total: USD 5,000 to red_darkin and USD 7,500 to madara_; neither recipient individually received USD 10,000."
      },
      "dates": {
        "published": {
          "value": "2025-08",
          "precision": "month",
          "basis": "inferred",
          "source_id": "primary",
          "note": "Disclosure events appear August 13 and August 15, 2025. The sidebar shows August 15; month retained because first public day is ambiguous."
        },
        "public_disclosure": {
          "value": "2025-08",
          "precision": "month",
          "basis": "inferred",
          "source_id": "primary",
          "note": "Disclosure events appear August 13 and August 15, 2025. The sidebar shows August 15; month retained because first public day is ambiguous."
        },
        "reported": {
          "value": "2025-04-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2025-05-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Report marked Resolved June 3, 2025; exact deployment date is unknown. A later edited retest comment is not a deployment timestamp."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical primary publication, outside the preferred last-12-month window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://hackerone.com/reports/3113398",
          "title": "Support integration exposed internal Confluence documentation (report 3113398)",
          "type": "vendor",
          "author": "HackerOne and the credited researchers",
          "retrieved_at": "2026-10-03T08:59:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.hackerone.com/terms/disclosure-guidelines",
          "title": "Vulnerability Disclosure Standards: Bug Bounty payment denomination",
          "type": "platform",
          "author": "HackerOne",
          "retrieved_at": "2026-10-02T15:43:47Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T08:59:00Z",
        "method": "Freshly read the public vendor summary, expanded award events, accepted-retest and resolution events in the cloud browser. Technical and comment bodies remain redacted. Existing currency evidence retained without a fresh review; no target testing.",
        "limitations": [
          "Award events establish an award, not independently audited settlement.",
          "Exact fix-deployment date is unavailable; a Resolved status date is not treated as deployment.",
          "Technical report and comment bodies are redacted; interpretation is limited to the vendor’s public summary and event metadata.",
          "Exact access prerequisites and the corrective configuration are not disclosed; no specific identity provisioning or entitlement mechanism is established by the public summary."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-cloud-build-approval-toctou-2025",
      "title": "Cloud Build approval was not bound to immutable code",
      "organization": "Google",
      "product": "Google Cloud Build GitHub integration",
      "researchers": [
        "Adnan Khan"
      ],
      "cve_ids": [],
      "cwe_mappings": [
        {
          "id": "CWE-367",
          "basis": "analyst_mapping",
          "source_id": "primary",
          "note": "The source explicitly names a time-of-check/time-of-use vulnerability; numeric CWE mapping is editorial."
        }
      ],
      "category_id": "business-logic",
      "secondary_category_ids": [
        "cloud-security",
        "supply-chain",
        "authorization"
      ],
      "skillset_ids": [
        "approval-state-integrity",
        "concurrency-reasoning",
        "integration-threat-modeling",
        "pipeline-trust-modeling",
        "secrets-containment"
      ],
      "summary": "A researcher-reported USD 30,000 award illustrates a gap between approval of a contribution and selection of the code executed.",
      "root_cause": "The researcher compared the identity available to the approval event with the revision later selected by the build. Approval referred to mutable contribution state without preserving the exact reviewed version. The execution boundary therefore relied on an assumption that the approved and executed content remained identical.",
      "impact": "The controlled demonstration executed a newer, unreviewed revision. Access to secrets or cloud resources was a potential consequence of the build’s assigned privileges, not evidence that all pipelines exposed those assets.",
      "defensive_takeaways": [
        "Bind approval and execution to immutable content identities, with explicit confirmation when the intended revision is ambiguous.",
        "The researcher’s fix analysis describes check-to-commit binding and explicit commit selection; it does not establish a universal patch recipe.",
        "Limit build identity privileges and secret availability independently of human approval."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "January 28, 2025 - Awarded $30,000 Bounty",
        "evidence_location": "Disclosure Timeline",
        "usd_equivalent": null,
        "notes": "Older reference: public write-up predates the preferred 12-month window; original report was in 2024.",
        "type": "bug_bounty",
        "awarding_organization": "Google"
      },
      "dates": {
        "published": {
          "value": "2025-07-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": "2025-07-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Publication of this write-up; earliest disclosure elsewhere was not independently established."
        },
        "reported": {
          "value": "2024-11-13",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2025-01-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The researcher says Google marked the issue fixed on June 18, 2025. The exact deployment date is not established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Cash settlement date not independently established."
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Older reference, outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://adnanthekhan.com/posts/cloud-build-toctou/",
          "title": "Who's SHA is it Anyway: Bypassing Google Cloud Build Comment Control for $30,000",
          "type": "researcher",
          "author": "Adnan Khan",
          "retrieved_at": "2026-10-02T20:00:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T20:00:00Z",
        "method": "Re-read the approval model, observed build result, fix analysis and timeline; separated demonstrated behavior, conditional consequences and vendor fix-status confirmation.",
        "limitations": [
          "Researcher-reported award; cash settlement was not independently audited.",
          "The June 18, 2025 status change confirms the issue was marked fixed, not the exact deployment date.",
          "The public account’s broader security consequences depend on pipeline permissions; no universal secret exposure is established."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "nvidia-container-runtime-environment-trust-2025",
      "title": "NVIDIA container initialization inherited untrusted execution context",
      "organization": "NVIDIA",
      "product": "NVIDIA Container Toolkit",
      "researchers": [
        "Nir Ohfeld",
        "Shir Tamari"
      ],
      "cve_ids": [
        "CVE-2025-23266"
      ],
      "cwe_mappings": [
        {
          "id": "CWE-426",
          "basis": "source_explicit",
          "source_id": "vendor-advisory",
          "note": "Explicit classification in the vendor security advisory."
        }
      ],
      "category_id": "cloud-security",
      "secondary_category_ids": [
        "injection"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "summary": "ZDI awarded Wiz researchers USD 30,000 for this single Pwn2Own Berlin 2025 entry.",
      "root_cause": "A privileged container-initialization component inherited container-controlled execution context without sufficient separation from host authority.",
      "impact": "An untrusted container image could lead to code execution with elevated host permissions. Scope depends on runtime configuration; NVIDIA explicitly excludes systems using crun from this CVE.",
      "defensive_takeaways": [
        "Keep privileged runtime initialization independent of workload-controlled configuration.",
        "Use layered tenant isolation and verify vendor-specific runtime applicability before remediation."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_competition_entry",
        "type": "competition_award",
        "awarding_organization": "Trend Micro Zero Day Initiative / Pwn2Own Berlin",
        "status": "awarded",
        "evidence_level": "organizer_confirmed",
        "source_id": "competition-results",
        "evidence_quote": "This unique bug earns them $30,000",
        "evidence_location": "Named Wiz researchers’ entry in the organizer’s dated daily results",
        "usd_equivalent": null,
        "notes": "One competition-entry award, not the researchers’ event total. Official rules specify US currency; recipient allocation and actual cash settlement are unverified."
      },
      "dates": {
        "published": {
          "value": "2025-07-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-report",
          "note": "Primary research article publication; earlier competition results are separately dated."
        },
        "public_disclosure": {
          "value": "2025-05-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Public demonstration and result; vendor technical advisory followed later."
        },
        "reported": {
          "value": "2025-05-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-report",
          "note": "The researchers explicitly date this CVE’s initial vendor report at Pwn2Own to May 17. ZDI separately lists June 5 as its vendor-notification date; that later coordination event is not substituted for the initial report."
        },
        "awarded": {
          "value": "2025-05-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": "Award announced for the named individual entry."
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Vendor bulletin initially released July 15, 2025 and later revised affected products and fixes; the exact release date for each patched component was not established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2025-05-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "competition-results",
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference: published before October 2, 2025."
      },
      "sources": [
        {
          "id": "researcher-report",
          "url": "https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape",
          "title": "NVIDIAScape: NVIDIA Container Toolkit CVE-2025-23266",
          "type": "researcher",
          "author": "Nir Ohfeld and Shir Tamari / Wiz Research",
          "retrieved_at": "2026-10-02T17:39:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "competition-results",
          "url": "https://www.zerodayinitiative.com/blog/2025/5/17/pwn2own-berlin-2025-day-three-results",
          "title": "Pwn2Own Berlin 2025 daily results",
          "type": "competition_organizer",
          "author": "Dustin Childs / Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:39:00Z",
          "supports": [
            "reward",
            "dates",
            "impact"
          ]
        },
        {
          "id": "competition-rules",
          "url": "https://www.zerodayinitiative.com/Pwn2OwnBerlin2025Rules.html",
          "title": "Pwn2Own Berlin 2025 rules",
          "type": "competition_organizer",
          "author": "Trend Micro Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:39:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "vendor-advisory",
          "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5659",
          "title": "NVIDIA Container Toolkit security bulletin, July 2025",
          "type": "vendor",
          "author": "NVIDIA PSIRT",
          "retrieved_at": "2026-10-02T17:39:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "zdi-advisory",
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-626/",
          "title": "ZDI-25-626 NVIDIA Container Toolkit advisory",
          "type": "competition_organizer",
          "author": "Zero Day Initiative",
          "retrieved_at": "2026-10-02T17:39:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "researcher-report",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T17:39:00Z",
        "method": "Read the researcher’s explicit CVE-to-Pwn2Own submission timeline and matched its date, product and named researchers to the organizer’s individual-entry award; corroborated CVE and scope with vendor guidance. Official rules establish USD denomination.",
        "limitations": [
          "Historical technical publication, outside the preferred twelve-month window.",
          "One awarded competition entry shared by two named researchers; recipient splits and cash-transfer date are unknown.",
          "NVIDIA credits an additional finder, without assigning that person this competition award.",
          "Vendor bulletin was updated after initial disclosure; affected configurations and product-specific fixed releases should be read there."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "google-idx-worker-message-trust-2025",
      "title": "Google IDX worker messaging crossed browser trust boundaries",
      "organization": "Google",
      "product": "Project IDX / Cloud Workstations",
      "researchers": [
        "sudi (Sudistark)"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "client-security",
      "secondary_category_ids": [
        "injection"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "integration-threat-modeling",
        "untrusted-input-handling",
        "defensive-evidence-writing"
      ],
      "summary": "A browser-IDE trust-boundary report received a USD 22,500 award.",
      "root_cause": "The messaging boundary treated caller-influenced context as authority for extension-worker operations. Browser framing permission did not independently establish that embedded content should control the worker.",
      "impact": "The researcher demonstrated script execution in a worker, without direct DOM access. Same-origin requests were described as a possible consequence; broader account takeover was not established. The reproduced award notice limits severity because prior access to an affected resource was required.",
      "defensive_takeaways": [
        "Bind messaging trust to a verified origin and context.",
        "Review nested rendering and worker privileges together.",
        "Validate message authority independently of framing permission and keep untrusted rendered content separate from privileged extension operations."
      ],
      "reward": {
        "amount": 22500,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Google",
        "evidence_level": "researcher_reported_with_vendor_quote",
        "source_id": "award-image",
        "evidence_quote": "Google Vulnerability Reward Program panel has decided to issue a reward of $22500.00 for your report.",
        "evidence_location": "Researcher-published award email image, central award paragraph",
        "usd_equivalent": null,
        "notes": "The image states a $22,500 award. USD follows Google web VRP denomination documented by google-usd-context; no currency conversion. Bonus mentioned but not separately itemized. Settlement date unknown."
      },
      "dates": {
        "published": {
          "value": "2025-07-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Date displayed by the researcher article."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2024",
          "precision": "year",
          "basis": "inferred",
          "source_id": "primary",
          "note": "Article says the report was submitted last year; year inferred from its 2025 publication header."
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://sudistark.github.io/2025/07/02/idx.html",
          "title": "XSS in Google IDX Workstation",
          "type": "researcher",
          "author": "sudi (Sudistark)",
          "retrieved_at": "2026-10-03T05:19:42Z",
          "supports": [
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "award-image",
          "url": "https://sudistark.github.io/tmp/cdn-images/Pasted%20image%2020250729220436.png",
          "title": "Researcher-published Google award email for IDX report",
          "type": "researcher",
          "author": "sudi (Sudistark), reproducing a Google award notice",
          "retrieved_at": "2026-10-02T15:12:00Z",
          "supports": [
            "reward",
            "impact"
          ]
        },
        {
          "id": "google-usd-context",
          "url": "https://bughunters.google.com/blog/increasing-google-alphabet-vrp-rewards-up-to-151515",
          "title": "Google and Alphabet VRP reward-denomination announcement, July 11, 2024",
          "type": "vendor",
          "author": "Sam Erb and Krzysztof Kotowicz / Google",
          "retrieved_at": "2026-10-02T15:14:47Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T05:19:42Z",
        "method": "Fresh-read the article; retained previously inspected award-image and currency evidence without advancing their retrieval times. No testing performed.",
        "limitations": [
          "Award evidence is not an independently audited cash receipt.",
          "The image is researcher-published, not independently retrieved vendor correspondence.",
          "Exact original-report, award, payment, fix and first-disclosure dates are unavailable. The linked Bug Hunters report returned no readable text.",
          "Article credits Matan Berson for the underlying discovery and Sreeram and Sivanesh for supporting research; recipient split is not stated.",
          "Parts of the explanation use a local Code OSS reconstruction; the author acknowledges incomplete historical IDX notes. It is not a verified account of current product behavior."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "google-actifio-driver-service-identity-isolation-2025",
      "title": "Actifio driver execution exposed excessive shared-service authority",
      "organization": "Google",
      "product": "Actifio cloud backup service",
      "researchers": [
        "Sivanesh Ashok",
        "Sreeram KL",
        "Raidh"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "cloud-security",
      "secondary_category_ids": [
        "authorization"
      ],
      "skillset_ids": [
        "cloud-iam-review",
        "machine-identity-governance",
        "secrets-containment",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "One Actifio report earned USD 10,000 after a collaboration multiplier.",
      "root_cause": "Insufficient separation between user-supplied driver code and a privileged shared service identity.",
      "impact": "Researchers demonstrated execution and observed service-account access across many compute instances. Broader customer-project compromise was claimed, not independently verified.",
      "defensive_takeaways": [
        "Isolate extension execution from service credentials.",
        "Scope delegated identities to the minimum tenant and resource set.",
        "Distinguish observed permissions from untested downstream impact."
      ],
      "reward": {
        "amount": 10000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Google",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "Google VRP rewarded us $5,000 as the base reward. … they doubled the reward to $10,000.",
        "evidence_location": "Actifio section, final paragraph; ellipsis joins excerpts",
        "usd_equivalent": null,
        "notes": "One report: USD 5,000 base doubled by a collaboration grant. The separate Dataprep finding in this article received no cash bounty. USD denomination follows official Google program context; recipient split and cash settlement unknown."
      },
      "dates": {
        "published": {
          "value": "2025-05-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The narrative gives approximate historical context but no distinct submission date for this Actifio report."
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://stazot.com/?article=dataprep-actifio-jar-swapping-rce",
          "title": "Two RCEs in Google Cloud products and Nike Air Max 90s",
          "type": "researcher",
          "author": "Sivanesh Ashok",
          "retrieved_at": "2026-10-02T15:31:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "google-usd-context",
          "url": "https://security.googleblog.com/2017/03/vrp-news-from-nullcon.html",
          "title": "VRP news from Nullcon: Google web VRP USD denomination",
          "type": "vendor",
          "author": "Josh Armour / Google",
          "retrieved_at": "2026-10-02T15:11:49Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T15:31:00Z",
        "method": "Full researcher article read in the cloud browser after text retrieval returned only the page shell. Award paragraph isolated from the unrelated unrewarded finding.",
        "limitations": [
          "Award is researcher-reported; no cash receipt or per-contributor split is supplied.",
          "Exact original-report, award, payment, fix and first-disclosure dates are unavailable.",
          "Broad cross-customer impact is the researcher’s assessment, not evidence of customer-data extraction."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "hackerone-report-json-serialization-data-exposure-2025",
      "title": "Framework serialization change exposed private HackerOne user attributes",
      "organization": "HackerOne",
      "product": "HackerOne report serialization",
      "researchers": [
        "avinash_"
      ],
      "cve_ids": [],
      "cwe_mappings": [
        {
          "id": "CWE-200",
          "basis": "source_explicit",
          "source_id": "primary",
          "note": "The vendor explicitly labels the report Information Disclosure (CWE-200)."
        }
      ],
      "category_id": "information-exposure",
      "secondary_category_ids": [
        "authorization"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "untrusted-input-handling",
        "authorization-modeling",
        "patch-verification"
      ],
      "summary": "A framework upgrade exposed private contributor attributes in public report responses. The vendor confirmed a USD 25,000 award; the public report supplies the underlying serialization and test-normalization explanation.",
      "root_cause": "The vendor explains that an internal user object and a sanitized public representation shared a field name under different Ruby key types. Earlier serialization retained only the sanitized representation; the upgrade emitted both. Snapshot tests reparsed the response and discarded the earlier duplicate field, concealing sensitive data present in the raw response. The affected context was a disclosed report with a reporter or team-member summary. This was an application output-boundary failure exposed by a framework behavior change, not an AI-agent defect.",
      "impact": "The vendor reproduced private-attribute exposure. The public report describes personal and security-sensitive account attributes, but does not demonstrate account takeover or establish an affected-user count or wider exploitation. The vendor announced a deployed fix on February 21, 2025; the researcher retested and observed only intended public attributes for team and reporter summaries. The exact code change is not disclosed.",
      "defensive_takeaways": [
        "Editorial lesson: construct public responses from explicit safe fields rather than relying on later serialization to overwrite an internal object.",
        "Editorial lesson: test both raw serialized output and parsed structure; normalization can hide duplicate fields and sensitive data.",
        "Editorial lesson: treat framework upgrades as changes to security-relevant output semantics, and exercise nested representations with private-field exclusion assertions."
      ],
      "reward": {
        "amount": 25000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "HackerOne",
        "status": "awarded",
        "evidence_level": "vendor_confirmed",
        "source_id": "primary",
        "evidence_quote": "Reward: $25,000",
        "evidence_location": "Primary article award statement",
        "usd_equivalent": null,
        "notes": "Vendor confirms the individual report’s reward; the public report records the award event on February 21, 2025, while settlement remains unreported. The award article uses a dollar sign; current official HackerOne standards supply USD context only. Exhibit C reproduces guideline version 1.2 dated July 29, 2019 and specifies USD on printed page 12, supplying historical platform context rather than individual payment proof."
      },
      "dates": {
        "published": {
          "value": "2025-04-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "technical-report",
          "note": "Public technical report disclosure date; the later vendor case study was published June 24, 2025."
        },
        "public_disclosure": {
          "value": "2025-04-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "technical-report",
          "note": null
        },
        "reported": {
          "value": "2025-02-19",
          "precision": "day",
          "basis": "explicit",
          "source_id": "technical-report",
          "note": null
        },
        "awarded": {
          "value": "2025-02-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "technical-report",
          "note": "Public timeline records the bounty event; the vendor case study establishes its USD 25,000 amount. Separate retest compensation is not included."
        },
        "fixed": {
          "value": "2025-02-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "technical-report",
          "note": "Vendor deployment confirmation and successful researcher retest appear on this day; exact deployment time is not established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical primary publication, outside the preferred last-12-month window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.hackerone.com/blog/hai-insight-agent-case-study",
          "title": "We’re Running Hai Insight Agent on Our Own Bug Bounty Program – See it in Action",
          "type": "vendor",
          "author": "Crystal Hazen / HackerOne",
          "retrieved_at": "2026-10-03T08:59:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.hackerone.com/terms/disclosure-guidelines",
          "title": "Vulnerability Disclosure Standards",
          "type": "platform",
          "author": "HackerOne",
          "retrieved_at": "2026-10-02T23:03:50Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "historical-currency-context",
          "url": "https://www.carahsoft.com/buy/gsa-schedule-contracts/approved-csas/docFileDownload/286450/24c3653f-9d13-4944-8f2e-5baa23efa63c",
          "title": "HackerOne terms and disclosure guidelines in official reseller GSA contract attachment, Exhibit C",
          "type": "platform",
          "author": "HackerOne / Carahsoft (contract attachment)",
          "retrieved_at": "2026-10-02T23:05:44Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "technical-report",
          "url": "https://hackerone.com/reports/3000510",
          "title": "Public report 3000510: private user attributes exposed in report serialization",
          "type": "vendor",
          "author": "HackerOne and avinash_",
          "retrieved_at": "2026-10-03T08:59:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T08:59:00Z",
        "method": "Freshly read the vendor case study and the public technical report in the cloud browser, including vendor root-cause explanation and timeline. No target testing. Existing denomination sources retained without a fresh review.",
        "limitations": [
          "Award evidence does not establish settlement; the USD 25,000 amount comes from the case study, while the report hides the bounty amount.",
          "The technical report names the earlier Rails version as 6.1.7.9; the later case study says 6.1.7.10. Both identify the upgrade to 7.1.5.1; the discrepancy is unresolved.",
          "The case study describes retest validation within an hour, but visible retest-request and completion timestamps are about 72 minutes apart. Edited timeline timestamps and deployment timing limit precise duration comparisons.",
          "The public sources do not establish exact authentication prerequisites, affected-user count, a code-level patch, or successful account compromise.",
          "Currency context includes currently reviewed standards dated July 27, 2026 and historical platform guidelines; neither independently proves individual settlement."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "youtube-creator-email-authorization-2025",
      "title": "YouTube creator metadata exposed private email addresses",
      "organization": "Google",
      "product": "YouTube Studio and Content ID APIs",
      "researchers": [
        "Arvin Shivram (Brutecat)"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "A monetized-channel account could access another monetized creator’s private email through inconsistent cross-API authorization. The researcher reports a USD 20,000 award.",
      "root_cause": "Ordinary sensitive-field checks appeared effective, but an alternate metadata path exposed a cross-service association. The researcher then questioned whether monetized creator accounts inherited rights intended for specialist rights-management accounts.",
      "impact": "The demonstrated disclosure concerned the email stored when the target channel became monetized, which may differ from its current email. Broader phishing consequences were potential impact, not demonstrated account compromise.",
      "defensive_takeaways": [
        "Editorial lesson: check privacy guarantees across alternate response paths and linked services.",
        "Editorial lesson: separate caller eligibility for an API from authority over each returned object."
      ],
      "reward": {
        "amount": 20000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Google",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "Panel awards $13,337. … Panel awards an additional $6,663.",
        "evidence_location": "Timeline, January 21 and January 23 entries; ellipsis joins excerpts",
        "usd_equivalent": null,
        "notes": "USD 13,337 initial award plus USD 6,663 adjustment for this same report; awarded date records the final adjustment."
      },
      "dates": {
        "published": {
          "value": "2025-03-13",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": "2025-03-13",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "reported": {
          "value": "2024-12-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2025-01-23",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Vendor confirmed the issue fixed on February 21, 2025; actual deployment date is not established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://brutecat.com/articles/youtube-creator-emails/",
          "title": "Disclosing YouTube Creator Emails for a $20k Bounty",
          "type": "researcher",
          "author": "Arvin Shivram (Brutecat)",
          "retrieved_at": "2026-10-03T05:09:57Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T05:09:57Z",
        "method": "Fresh read of the primary researcher article through web text extraction; compared prerequisites, authorization boundary, demonstrated impact and remediation chronology with the existing record. No target testing or exploit reproduction.",
        "limitations": [
          "Award is reported by the cited source; cash settlement is not independently audited.",
          "The article does not supply implementation-level patch details or establish actual deployment timing."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "gitlab-recovery-address-binding-cve-2023-7028",
      "title": "GitLab recovery delivery lacked verified-address binding",
      "organization": "GitLab",
      "product": "GitLab Community and Enterprise Editions",
      "researchers": [
        "asterion04"
      ],
      "cve_ids": [
        "CVE-2023-7028"
      ],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "authorization"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "authorization-modeling",
        "secure-parser-review",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "summary": "One recovery report received USD 35,000 across two award events.",
      "root_cause": "A secondary-address recovery feature expanded delivery choices without consistently preserving verified-address ownership. The vendor attributes the regression to email verification; recovery authorization must remain bound to trusted account state as features change.",
      "impact": "Unauthorized password changes could lead to account takeover. Enforced second-factor authentication still prevented login, but did not prevent password reset. Offering SSO alone did not eliminate exposure when password authentication remained available.",
      "defensive_takeaways": [
        "Bind recovery delivery to verified account state and validate security-sensitive input contracts.",
        "Review recovery paths independently of primary authentication and optional SSO.",
        "Vendor remediation added end-to-end reset tests covering address handling, email generation and content; review the whole recovery contract rather than one validation function.",
        "Separate patch deployment from compromise assessment; apply the vendor’s incident-response guidance where compromise is suspected."
      ],
      "reward": {
        "amount": 35000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "GitLab",
        "status": "awarded",
        "evidence_level": "vendor_confirmed",
        "source_id": "primary",
        "evidence_quote": "rewarded asterion04 with a $1,000 bounty. … rewarded asterion04 with a $34,000 bounty.",
        "evidence_location": "Public award events December 22, 2023 and January 12, 2024; ellipsis joins fragments.",
        "usd_equivalent": null,
        "notes": "USD 1,000 initial plus USD 34,000 additional award for one report. Dollar notation uses HackerOne policy currency context; cash receipt unverified."
      },
      "dates": {
        "published": {
          "value": "2025-02-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Detailed report publication, later than the vendor advisory."
        },
        "public_disclosure": {
          "value": "2024-01-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Public vendor advisory; detailed report followed February 26, 2025."
        },
        "reported": {
          "value": "2023-12-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2024-01-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Final award event; initial award December 22, 2023."
        },
        "fixed": {
          "value": "2024-01-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Public patched release. GitLab.com was patched earlier; its exact deployment date is not supplied."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical primary publication, outside the preferred last-12-month window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://hackerone.com/reports/2293343",
          "title": "Account Takeover via Password Reset without user interactions",
          "type": "vendor",
          "author": "GitLab and asterion04",
          "retrieved_at": "2026-10-02T16:00:19Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "release",
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-16-7-2-released/",
          "title": "GitLab Critical Security Release: 16.7.2, 16.6.4, 16.5.6",
          "type": "vendor",
          "author": "GitLab",
          "retrieved_at": "2026-10-02T21:18:25Z",
          "supports": [
            "dates",
            "cve",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.hackerone.com/terms/disclosure-guidelines",
          "title": "Vulnerability Disclosure Standards: Bug Bounty payment denomination",
          "type": "platform",
          "author": "HackerOne",
          "retrieved_at": "2026-10-02T15:43:47Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T21:18:25Z",
        "method": "Original public report and both award events read in the cloud browser; official vendor release notes independently corroborate the CVE, impact boundary and patched release. Re-read the vendor FAQ to distinguish secondary-address regression, second-factor and SSO boundaries, and documented regression-test coverage.",
        "limitations": [
          "Award events do not establish cash settlement.",
          "The report UI has no CVE field value; CVE association comes from the matching vendor advisory.",
          "Detailed report publication is not the first public advisory date.",
          "The advisory’s historical observation of no detected abuse on vendor-managed platforms does not establish present-day absence of compromise or the state of self-managed deployments."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "youtube-pixel-recorder-identity-privacy-2025",
      "title": "YouTube and Pixel Recorder exposed cross-product identity links",
      "organization": "Google",
      "product": "YouTube and Pixel Recorder",
      "researchers": [
        "Arvin Shivram (Brutecat)",
        "Nathan (schizo.org)"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "One cross-product privacy report received USD 3,133 and a USD 7,500 adjustment, totaling USD 10,633.",
      "root_cause": "Cross-product identifier exposure and insufficient field-level privacy controls weakened account pseudonymity.",
      "impact": "Researchers reported that private email addresses associated with YouTube users could be revealed. No mass breach is established.",
      "defensive_takeaways": [
        "Treat cross-product identifiers as sensitive correlation data.",
        "Require entitlement before returning identity attributes.",
        "Verify remediation across every affected component."
      ],
      "reward": {
        "amount": 10633,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Google",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "Panel awards $3,133 … Panel awards an additional $7,500",
        "evidence_location": "Timeline, November 5 and December 12, 2024; ellipsis joins excerpts",
        "usd_equivalent": null,
        "notes": "One report: December 3 entry explicitly says it returned for additional reward consideration. Headline rounds to $10,000. Exact arithmetic is $10,633. USD uses Google web VRP denomination documented by google-usd-context. Awarded, not confirmed paid."
      },
      "dates": {
        "published": {
          "value": "2025-02-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": "2025-02-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "reported": {
          "value": "2024-09-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2024-12-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Final additional award; initial award was November 5, 2024."
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Researcher confirmed both components fixed on February 9, 2025; actual deployment date is not supplied."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://brutecat.com/articles/leaking-youtube-emails/",
          "title": "Leaking the email of any YouTube user for $10,000",
          "type": "researcher",
          "author": "Arvin Shivram and Nathan",
          "retrieved_at": "2026-10-02T15:12:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "google-usd-context",
          "url": "https://bughunters.google.com/blog/increasing-google-alphabet-vrp-rewards-up-to-151515",
          "title": "Google and Alphabet VRP reward-denomination announcement, July 11, 2024",
          "type": "vendor",
          "author": "Sam Erb and Krzysztof Kotowicz / Google",
          "retrieved_at": "2026-10-02T15:14:47Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T15:14:47Z",
        "method": "Primary source reviewed; individual award and attribution checked. Historical defensive summary only. Official 2024 program announcement was read in the cloud browser for USD denomination only; its advertised maximum is not award evidence.",
        "limitations": [
          "Award evidence is not an independently audited cash receipt.",
          "The source uses dollar notation, with USD established from Google program context.",
          "No public report ID, recipient split, or exact fix-deployment date is provided.",
          "Separate from the March 2025 creator-metadata report and its USD 20,000 award."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "hackerone-private-program-graphql-object-authorization-2025",
      "title": "GraphQL object authorization exposed private-program metadata",
      "organization": "HackerOne",
      "product": "HackerOne GraphQL object access",
      "researchers": [
        "haxta4ok00"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "HackerOne awarded USD 25,000 in 2022 for private-program GraphQL metadata exposure; the report became public in January 2025 (primary).",
      "root_cause": "A GraphQL object lookup failed to preserve private-program visibility for associated metadata (primary). The researcher described an unauthenticated request and triage validated the report. Exposure depended on resolving a valid program-associated object; the public record does not establish equal reachability across every private-program type. Conceptually, resolving an object is distinct from authorizing its disclosure. The exact omitted check and code-level repair are not public.",
      "impact": "The researcher demonstrated private-program metadata exposure. HackerOne’s internal investigation additionally determined that report titles could be accessed and raised severity to critical; title access was a vendor-assessed consequence, not the researcher’s demonstrated result in the visible evidence. HackerOne said it found no exploitation beyond the demonstration (primary). Full report-body access is not established.",
      "defensive_takeaways": [
        "Editorial design lesson: independently enforce visibility on object lookup, returned fields and related objects, including unauthenticated access paths.",
        "Editorial privacy lesson: program metadata and report titles can disclose confidential information even when report bodies remain protected.",
        "HackerOne marked the report Resolved on July 5, 2022 (primary). Treat that as resolution evidence; the deployment date and implementation-level remediation remain unknown."
      ],
      "reward": {
        "amount": 25000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "HackerOne",
        "status": "awarded",
        "evidence_level": "vendor_confirmed",
        "source_id": "primary",
        "evidence_quote": "rewarded haxta4ok00 with a $25,000 bounty.",
        "evidence_location": "Bounty event July 5, 2022 at 16:15 UTC, activity 17427955.",
        "usd_equivalent": null,
        "notes": "One report award, not verified cash receipt. USD is contextual from HackerOne’s platform-wide payment policy reviewed in October 2026, more than four years after the July 2022 award; it does not independently establish that payment’s denomination or settlement."
      },
      "dates": {
        "published": {
          "value": "2025-01-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Public disclosure event activity-32092519; the underlying report and award are from 2022."
        },
        "public_disclosure": {
          "value": "2025-01-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "reported": {
          "value": "2022-06-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2022-07-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Report status changed to Resolved on July 5, 2022; exact deployment time is not stated."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical primary publication, outside the preferred last-12-month window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://hackerone.com/reports/1618347",
          "title": "GraphQL object authorization exposed private-program metadata (report 1618347)",
          "type": "vendor",
          "author": "HackerOne and the credited researchers",
          "retrieved_at": "2026-10-03T05:30:46Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.hackerone.com/terms/disclosure-guidelines",
          "title": "Vulnerability Disclosure Standards: Bug Bounty payment denomination",
          "type": "platform",
          "author": "HackerOne",
          "retrieved_at": "2026-10-03T05:30:46Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T05:30:46Z",
        "method": "Freshly read the rendered public report, researcher demonstration, vendor triage/investigation statements and award/disclosure events in the cloud browser; independently read platform currency policy. Omitted payloads and private-program details.",
        "limitations": [
          "Award events establish an award, not independently audited settlement; later platform-wide currency policy is contextual evidence.",
          "Exact fix-deployment date is unavailable; Resolved status is not treated as deployment.",
          "Code-level patch details are not public. Vendor investigation supports possible report-title access; the visible researcher evidence demonstrates metadata exposure.",
          "The researcher expressed uncertainty about coverage of fully private programs. The record does not generalize exposure to every private-program category.",
          "Updated comment timestamps differ from original event dates."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "litespeed-cache-user-simulation-authentication-2024",
      "title": "LiteSpeed Cache privileged user simulation relied on weak security tokens",
      "organization": "LiteSpeed Technologies",
      "product": "LiteSpeed Cache WordPress plugin",
      "researchers": [
        "John Blackbourn"
      ],
      "cve_ids": [
        "CVE-2024-28000"
      ],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "authorization"
      ],
      "skillset_ids": [
        "security-token-design",
        "identity-lifecycle-review",
        "authorization-modeling",
        "patch-verification"
      ],
      "summary": "Patchstack confirmed a USD 14,400 Zero Day award for an authentication-boundary flaw.",
      "root_cause": "Privileged user simulation relied on a predictable, reusable token without adequate context binding.",
      "impact": "Unauthenticated users could obtain administrator privileges on affected installations. The advisory identifies an operating-system limitation, so plugin installation totals do not establish affected-site counts.",
      "defensive_takeaways": [
        "Use cryptographically secure token generation, explicit authorization, context binding and limited lifetimes.",
        "Treat impersonation and user-simulation features as privileged authentication boundaries."
      ],
      "reward": {
        "amount": 14400,
        "currency": "USD",
        "scope": "single_vulnerability",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Patchstack Zero Day program",
        "evidence_level": "platform_confirmed",
        "source_id": "platform-advisory",
        "evidence_quote": "Patchstack Zero Day program has awarded the researcher $14,400 USD in cash.",
        "evidence_location": "Opening advisory paragraphs.",
        "usd_equivalent": null,
        "notes": "Records the explicitly isolated Zero Day component. Later platform sources report USD 16,400 paid for this single finding; the USD 2,000 difference is not apportioned or counted separately. The researcher acknowledges receiving payment; exact component settlement dates are unknown."
      },
      "dates": {
        "published": {
          "value": "2024-08-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "platform-advisory",
          "note": null
        },
        "public_disclosure": {
          "value": "2024-08-19",
          "precision": "day",
          "basis": "explicit",
          "source_id": "platform-advisory",
          "note": "Initial platform vulnerability-database publication preceded the full advisory."
        },
        "reported": {
          "value": "2024-08-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "platform-advisory",
          "note": "Report received by Patchstack; vendor contacted August 5."
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": "2024-08-13",
          "precision": "day",
          "basis": "explicit",
          "source_id": "platform-advisory",
          "note": "Release of version 6.4."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Payment acknowledged in September 6, 2024 interview, without a settlement date."
        },
        "award_announced": {
          "value": "2024-08-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "platform-advisory",
          "note": "Direct award amount stated in the advisory; earliest announcement not independently established."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred publication window."
      },
      "sources": [
        {
          "id": "platform-advisory",
          "url": "https://patchstack.com/articles/critical-privilege-escalation-in-litespeed-cache-plugin-affecting-5-million-sites/",
          "title": "LiteSpeed Cache CVE-2024-28000 coordinated advisory",
          "type": "platform",
          "author": "Rafie Muhammad / Patchstack",
          "retrieved_at": "2026-10-02T16:42:07Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "platform-interview",
          "url": "https://patchstack.com/articles/interview-with-john-blackbourn/",
          "title": "Interview with John Blackbourn",
          "type": "platform",
          "author": "Maciek Palmowski / Patchstack",
          "retrieved_at": "2026-10-02T16:42:07Z",
          "supports": [
            "reward",
            "dates"
          ]
        },
        {
          "id": "platform-retrospective",
          "url": "https://patchstack.com/whitepaper/state-of-wordpress-security-in-2025/",
          "title": "State of WordPress Security 2025",
          "type": "platform",
          "author": "Patchstack",
          "retrieved_at": "2026-10-02T16:42:07Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "platform-advisory",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T16:42:07Z",
        "method": "Read platform advisory, coordinated timeline, researcher interview and later platform retrospective.",
        "limitations": [
          "Exact award and payment dates are absent. The recorded component is not the later reported total.",
          "The advisory describes Windows-specific limitations.",
          "The disclosed patch added token checks and lifetime controls; the researcher’s recommended random-generator improvement was deferred for compatibility."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "github-reflection-method-authority-cve-2024-0200",
      "title": "GitHub unsafe reflection crossed method and credential boundaries",
      "organization": "GitHub",
      "product": "GitHub.com and GitHub Enterprise Server",
      "researchers": [
        "Ngo Wei Lin (Creastery), STAR Labs"
      ],
      "cve_ids": [
        "CVE-2024-0200"
      ],
      "cwe_mappings": [],
      "category_id": "injection",
      "secondary_category_ids": [
        "information-exposure"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "secrets-containment",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "summary": "A historical unsafe-reflection finding exposed production-container credentials on GitHub.com. GitHub's award retrospective links its highest single paid reward of 2023 to the incident notice. The researcher later published technical analysis and separately described GHES execution impact. This 2024 disclosure remains useful in 2026 for reviewing input-to-operation authority, runtime secret containment and deployment-specific evidence.",
      "root_cause": "Externally controlled method selection was insufficiently restricted to intended operations. The researcher traces this unsafe reflection to a boundary where selection data acquired internal application authority; the GHES advisory corroborates the weakness class. Authentication and organization ownership limited reachability but did not make unrestricted operation selection safe.",
      "impact": "GitHub confirms production-container credential exposure and assessed with high confidence that the issue had not been previously exploited and impact was isolated to the researcher. The researcher separately reports GHES code-execution potential; GitHub's GHES advisory corroborates that impact class and requires an authenticated organization-owner account. These sources do not establish code execution on GitHub.com. No secret values or private victim data are retained.",
      "defensive_takeaways": [
        "Constrain dynamic operation selection to an explicit permitted set, with authorization for the selected operation rather than relying only on the caller's authenticated role.",
        "Minimize secrets available to each process and define narrow response-data contracts so an unexpected internal result cannot disclose ambient credentials.",
        "Treat credential exposure as requiring coordinated rotation and dependency review; design recovery procedures that limit disruption.",
        "For 2026 framework reviews, assess input-to-operation authority separately from input format and keep hosted-service observations distinct from self-managed deployment impact."
      ],
      "reward": {
        "amount": 75000,
        "currency": "USD",
        "scope": "single_vulnerability",
        "status": "paid",
        "evidence_level": "vendor_confirmed",
        "source_id": "award-retrospective",
        "evidence_quote": "We paid out our highest single reward to date in 2023—at $75,000!",
        "evidence_location": "Decade milestones, item 9. The words 'our highest single reward' link directly to the January 16, 2024 incident notice.",
        "usd_equivalent": null,
        "notes": "One vendor-reported paid reward linked to this incident, not a program ceiling or total. USD is a contextual inference: the award source uses $ only. GitHub's January 9, 2017 program article, updated June 25, 2021, explicitly uses USD; HackerOne's guidelines version 1.3, updated July 27, 2026, also specify USD. These earlier program-wide and later platform-wide statements are not contemporaneous 2023 payment evidence and do not independently prove this award's currency or settlement. No conflicting denomination was found in the reviewed sources. The retrospective establishes the amount and payment year; no separate award is inferred for the follow-up GHES impact.",
        "type": "bug_bounty",
        "awarding_organization": "GitHub"
      },
      "dates": {
        "published": {
          "value": "2024-05-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher",
          "note": "Detailed researcher publication and coordinated technical disclosure."
        },
        "public_disclosure": {
          "value": "2024-01-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-incident",
          "note": "Vendor incident notice; distinct from the later detailed researcher publication."
        },
        "reported": {
          "value": "2023-12-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-incident",
          "note": "Initial report. The researcher timeline separately dates the GHES execution-impact follow-up to December 28, 2023."
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The distinct award-decision date is not established; it is not substituted with the report or payment year."
        },
        "fixed": {
          "value": "2023-12-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-incident",
          "note": "GitHub.com fix only. The vendor incident notice and GHES release notes date GHES patches to January 16, 2024."
        },
        "paid": {
          "value": "2023",
          "precision": "year",
          "basis": "explicit",
          "source_id": "award-retrospective",
          "note": "Vendor explicitly says the single reward was paid in 2023; exact payment day and independent settlement evidence are unavailable."
        },
        "award_announced": {
          "value": "2024-06-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "award-retrospective",
          "note": "Publication date of the reviewed award retrospective, updated July 23, 2024; the earliest announcement date is not established."
        },
        "mitigated": {
          "value": "2023-12-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-incident",
          "note": "Credential rotation began after the GitHub.com fix; this is not a rotation-completion date."
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical 2024 detailed publication outside the preferred window. Classified against the existing October 3, 2026 inventory anchor; this addition is not a new vulnerability disclosure."
      },
      "sources": [
        {
          "id": "researcher",
          "url": "https://www.creastery.com/blog/sending-myself-github-com-environment-variables-and-ghes-shell/",
          "title": "GitHub.com's Environment Variables & GHES Shell",
          "type": "researcher",
          "author": "Ngo Wei Lin (Creastery)",
          "retrieved_at": "2026-10-04T23:31:13Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "award-retrospective",
          "url": "https://github.blog/security/vulnerability-research/10-years-of-the-github-security-bug-bounty-program/",
          "title": "10 years of the GitHub Security Bug Bounty Program",
          "type": "vendor",
          "author": "Jill Moné-Corallo / GitHub",
          "retrieved_at": "2026-10-04T23:30:54Z",
          "supports": [
            "reward",
            "dates"
          ]
        },
        {
          "id": "vendor-incident",
          "url": "https://github.blog/news-insights/company-news/rotating-credentials-for-github-com-and-new-ghes-patches/",
          "title": "Rotating credentials for GitHub.com and new GHES patches",
          "type": "vendor",
          "author": "Jacob DePriest / GitHub",
          "retrieved_at": "2026-10-04T23:31:32Z",
          "supports": [
            "dates",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "ghes-release",
          "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.3",
          "title": "GitHub Enterprise Server 3.11.3 release notes",
          "type": "vendor",
          "author": "GitHub",
          "retrieved_at": "2026-10-04T23:32:32Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "historical-currency-context",
          "url": "https://github.blog/news-insights/company-news/bug-bounty-anniversary-promotion-bigger-bounties-in-january-and-february/",
          "title": "Bug Bounty anniversary promotion: bigger bounties in January and February",
          "type": "vendor",
          "author": "Neil Matatall / GitHub",
          "retrieved_at": "2026-10-04T23:32:32Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "platform-currency-context",
          "url": "https://www.hackerone.com/terms/disclosure-guidelines",
          "title": "Vulnerability Disclosure Guidelines (Vulnerability Disclosure Standards)",
          "type": "platform",
          "author": "HackerOne",
          "retrieved_at": "2026-10-04T23:32:47Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-04T23:34:10Z",
        "method": "Read six public primary sources. Followed the vendor retrospective's single-reward link to the incident notice, reconciled its researcher credit with the linked researcher account and GHES advisory, and separately checked contextual denomination evidence. Promoted the prior 'GitHub highest single award in 2023' candidate after resolving technical attribution and contextual-currency gaps. No target interaction or exploit reproduction.",
        "limitations": [
          "Payment is vendor-reported, not an independently audited bank transfer. Exact award-decision and payment days are unknown.",
          "USD denomination is contextual inference from non-contemporaneous official evidence; neither currency-context source establishes the individual amount or settlement.",
          "The researcher describes the GHES execution-impact extension separately from the GitHub.com credential-exposure observation. The precise GHES demonstration and implementation details are not independently verified here.",
          "GitHub's assessment of no earlier exploitation is the vendor's investigation conclusion, not an independent guarantee.",
          "The record summarizes a patched historical case; review in 2026 does not imply current exposure or grant testing authorization."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-bard-workspace-output-boundary-2024",
      "title": "Bard Workspace integration weakened output-data boundaries",
      "organization": "Google",
      "product": "Bard Workspace integration",
      "researchers": [
        "Roni Carta",
        "Justin Gardner"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "ai-security",
      "secondary_category_ids": [
        "client-security",
        "injection"
      ],
      "skillset_ids": [
        "ai-authority-boundaries",
        "integration-threat-modeling",
        "untrusted-input-handling"
      ],
      "summary": "One Workspace data-disclosure finding within a broader research article earned USD 20,000.",
      "root_cause": "Generated content and browser output restrictions did not maintain the intended boundary around connected Workspace data.",
      "impact": "The researchers demonstrated disclosure of email content from a controlled account.",
      "defensive_takeaways": [
        "Independently constrain external destinations for sensitive model output.",
        "Review connector data access and rendering as a single end-to-end trust boundary."
      ],
      "reward": {
        "amount": 20000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Google",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "we ended up with a 20,000$ bounty",
        "evidence_location": "Google Workspace leakage through Bard section",
        "usd_equivalent": null,
        "notes": "Records the individual base award, not the article’s USD 50,000 aggregate. A USD 1,337 event bonus for this finding is stated separately."
      },
      "dates": {
        "published": {
          "value": "2024-03-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://depi.security/blog/20240304-google-hack-50000/",
          "title": "We Hacked Google A.I. for $50,000",
          "type": "researcher",
          "author": "Roni Carta",
          "retrieved_at": "2026-10-02T14:39:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T14:39:00Z",
        "method": "Primary public source read; individual award and source provenance verified. No target testing or exploit reproduction performed.",
        "limitations": [
          "Award is reported by the cited source; cash settlement is not independently audited."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "github-runner-image-build-isolation-2023",
      "title": "GitHub runner-image builds shared persistent infrastructure with untrusted workflows",
      "organization": "GitHub",
      "product": "GitHub Actions runner-image build infrastructure",
      "researchers": [
        "Adnan Khan"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "supply-chain",
      "secondary_category_ids": [
        "authorization"
      ],
      "skillset_ids": [
        "pipeline-trust-modeling",
        "secrets-containment",
        "approval-state-integrity",
        "defensive-evidence-writing"
      ],
      "summary": "An isolation misconfiguration exposed runner-image build infrastructure; the researcher reports a $20,000 payment.",
      "root_cause": "Contributor status was treated as sufficient trust for workflows using persistent self-hosted infrastructure. The researcher connected approval policy, runner reuse and privileged build context to identify a boundary failure between outside contributions and trusted image production.",
      "impact": "With contributor access under the affected configuration, the researcher demonstrated infrastructure access and build-secret exposure. Downstream compromise of distributed runner images remained a modeled consequence: intervening production controls were unknown.",
      "defensive_takeaways": [
        "Separate untrusted contribution processing from privileged build infrastructure and secrets.",
        "Bind review to the workflow being executed; prior contribution history is not continuing authorization.",
        "Use isolated disposable execution environments and independently verify release provenance."
      ],
      "reward": {
        "amount": 20000,
        "currency": "USD",
        "scope": "single_report",
        "status": "paid",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "I was awarded a $20,000 bug-bounty",
        "evidence_location": "Detailed article, GitHub Actions Runners introduction; payment corroborated by earlier post and timeline.",
        "usd_equivalent": null,
        "notes": "One report. GitHub’s official January 2017 article (updated June 2021) explicitly denominates standard bounties in USD; current platform guidelines corroborate context, not this individual award. Earlier researcher post explicitly says paid.",
        "type": "bug_bounty",
        "awarding_organization": "GitHub"
      },
      "dates": {
        "published": {
          "value": "2023-12-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Detailed article date."
        },
        "public_disclosure": {
          "value": "2023-12-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "announcement",
          "note": "Earlier public summary; not the detailed article date."
        },
        "reported": {
          "value": "2023-07-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2023-11-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": "2023-11-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "announcement",
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": "2023-07-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Detailed timeline: initial mitigations. Earlier summary says immediate fixes July 26; final technical fix date remains unknown."
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical detailed publication outside the preferred window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://adnanthekhan.com/2023/12/20/one-supply-chain-attack-to-rule-them-all/",
          "title": "One Supply Chain Attack to Rule Them All - Poisoning GitHub's Runner Images",
          "type": "researcher",
          "author": "Adnan Khan",
          "retrieved_at": "2026-10-02T23:01:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "announcement",
          "url": "https://adnanthekhan.com/2023/12/16/welcome-to-my-blog-there-is-more-to-come/",
          "title": "Welcome to my blog - there is more to come!",
          "type": "researcher",
          "author": "Adnan Khan",
          "retrieved_at": "2026-10-02T23:01:00Z",
          "supports": [
            "reward",
            "dates",
            "impact"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.hackerone.com/terms/disclosure-guidelines",
          "title": "Vulnerability Disclosure Guidelines",
          "type": "platform",
          "author": "HackerOne",
          "retrieved_at": "2026-10-02T23:01:00Z",
          "supports": [
            "reward"
          ]
        },
        {
          "id": "historical-currency-context",
          "url": "https://github.blog/news-insights/company-news/bug-bounty-anniversary-promotion-bigger-bounties-in-january-and-february/",
          "title": "Bug bounty anniversary promotion: Bigger bounties in January and February",
          "type": "vendor",
          "author": "Neil Matatall / GitHub",
          "retrieved_at": "2026-10-02T23:05:17Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T23:05:44Z",
        "method": "Read primary public disclosures and corroborating sources; checked individual award scope. No target interaction or exploit reproduction.",
        "limitations": [
          "Payment is researcher-reported, not independently audited.",
          "The reviewed HackerOne currency guideline is the current page, not a preserved 2023 policy snapshot.",
          "Resolution on November 14 does not establish an exact final remediation date."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "instagram-embedding-privileged-fallback-2023",
      "title": "Instagram embedding fallback changed the authorization context",
      "organization": "Meta",
      "product": "Instagram media embedding",
      "researchers": [
        "003random"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "error-response-design",
        "defensive-evidence-writing"
      ],
      "summary": "The researcher documents USD 14,500 for one report: a 10,000 base bounty and two event bonuses.",
      "root_cause": "A client-specific error path retrieved media under an elevated service identity, losing the original requester’s privacy constraints.",
      "impact": "Private post text and media could be exposed. The researcher did not establish the same effect for profile embedding.",
      "defensive_takeaways": [
        "Preserve requester authorization across error handling and fallback paths.",
        "Keep policy decisions consistent across client-specific code paths.",
        "Distinguish demonstrated data exposure from unverified adjacent features."
      ],
      "reward": {
        "amount": 14500,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Meta",
        "evidence_level": "researcher_reported",
        "source_id": "researcher-writeup",
        "evidence_quote": "$10,000 bounty\n$2,000 event bonus\n$2,500 additional event bonus (special scope)",
        "evidence_location": "Timeline: three September 25, 2022 entries for this report",
        "usd_equivalent": null,
        "notes": "One report: 10,000 base plus 2,000 and 2,500 bonuses. Classified as a bug bounty with event bonuses, not a separate placement prize. The article uses $; USD is contextualized by Facebook’s official program and BountyCon reporting, which predates this award."
      },
      "dates": {
        "published": {
          "value": "2023-10-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "This article is dated October 12, 2023. November 9, 2022 is permission to disclose, not proof of public publication."
        },
        "reported": {
          "value": "2022-09-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": "2022-09-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "All three report-linked reward components share this timeline date."
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The article says the issue was fixed, without an exact deployment date."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical research published October 2023, describing a 2022 report."
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://003random.com/posts/meta-bountycon-instagram-writeup/",
          "title": "How I Exposed Instagram's Private Posts by Blocking Users",
          "type": "researcher",
          "author": "003random",
          "retrieved_at": "2026-10-02T18:24:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Facebook Bug Bounty and BountyCon US-dollar reporting",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-02T18:24:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T18:24:00Z",
        "method": "Read researcher timeline, bounded impact and attributed vendor explanation. Summed only the three reward components explicitly attached to this report; used official program context for USD notation.",
        "limitations": [
          "Researcher-reported award, not independent vendor confirmation or audited settlement.",
          "Currency context comes from an earlier official program retrospective, not a reproduced award receipt.",
          "The account-restriction root cause is the researcher’s account of vendor clarification."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "meta-quest-oauth-redirect-confidentiality-2022",
      "title": "Meta Quest login migration lost OAuth credential confinement",
      "organization": "Meta",
      "product": "Meta Quest / Oculus account login",
      "researchers": [
        "Youssef Sammouda"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "authorization",
        "client-security"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "integration-threat-modeling",
        "security-token-design",
        "browser-isolation-review"
      ],
      "summary": "Meta confirms a USD 44,250 total award, including bonuses, for this Quest OAuth account-access report.",
      "root_cause": "The researcher compared login behavior across an identity-system migration. A previously permitted OAuth return destination began forwarding credentials through a changed redirect flow, losing an earlier containment control. Trust in the initial destination did not establish that the eventual recipient was authorized to receive the credential.",
      "impact": "The researcher reports exposure of a privileged first-party credential with account-access implications. Meta confirms possible account takeover requiring user interaction and says its investigation found no abuse. Those statements do not establish that customer accounts were actually compromised.",
      "defensive_takeaways": [
        "Reassess credential handling and destination trust whenever an identity provider or login flow changes.",
        "Preserve authorization checks through the full return flow; an initially permitted destination is not a guarantee about later recipients.",
        "Treat recommendations here as defensive design principles, not a reconstruction of the vendor’s undisclosed patch."
      ],
      "reward": {
        "amount": 44250,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Meta",
        "evidence_level": "vendor_confirmed",
        "source_id": "vendor-retrospective",
        "evidence_quote": "total of $44,250, including program bonuses",
        "evidence_location": "Connecting the Bug Bounty Community With the Metaverse, paragraph naming Youssef Sammouda’s Quest OAuth report",
        "usd_equivalent": null,
        "notes": "Vendor-confirmed total attached to one report. Researcher identifies BountyCon and Highest Impact Report bonuses but gives no component allocation; they are not added again. USD uses earlier official program context. Award confirmation does not establish cash settlement."
      },
      "dates": {
        "published": {
          "value": "2023-01-29",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Article date also appears in the researcher’s archive index; historical publication, not the archive’s separate January 2026 entries."
        },
        "public_disclosure": {
          "value": "2022-12-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-retrospective",
          "note": "Dated vendor summary precedes the technical article. The page’s December 2024 update explicitly concerns another report."
        },
        "reported": {
          "value": "2022-08-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": "2022-09-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Researcher’s dated total including bonuses; exact funds-transfer date is not established."
        },
        "fixed": {
          "value": "2022-09-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Researcher labels this as the Meta fix date. The article withholds details of a separate redirect component that it says was not fully fixed; this is not a claim that every component was remediated that day."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2022-12-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-retrospective",
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical January 2023 technical article describing a 2022 report and award."
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://ysamm.com/uncategorized/2023/01/29/account-takeover-of-facebook-oculus-accounts-due-to-first-party-access_token-stealing.html",
          "title": "Account takeover of Facebook/Oculus accounts due to First-Party access_token stealing",
          "type": "researcher",
          "author": "Youssef Sammouda",
          "retrieved_at": "2026-10-02T19:39:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "vendor-retrospective",
          "url": "https://about.fb.com/news/2022/12/metas-bug-bounty-program-2022/",
          "title": "Looking Back at Our Bug Bounty Program in 2022",
          "type": "vendor",
          "author": "Neta Oren / Meta",
          "retrieved_at": "2026-10-02T19:39:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Facebook Bug Bounty and BountyCon US-dollar reporting",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-02T18:24:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T19:39:00Z",
        "method": "Matched the researcher, Quest/Oculus OAuth issue and identical report-specific total across the researcher timeline and Meta retrospective. Summarized the migration-related trust failure without reproducing the operational flow.",
        "limitations": [
          "Bonus components are not individually quantified; the documented total is counted once.",
          "The technical article says an associated redirect detail was withheld because it was not fully fixed at publication. No current vulnerability or exact patch implementation is inferred.",
          "The vendor reports no evidence of abuse; this is not proof that abuse was impossible.",
          "Cash settlement is unverified; USD denomination uses earlier official program context."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "meta-account-verification-attempt-state-binding-2022",
      "title": "Meta account verification weakened linked SMS authentication state",
      "organization": "Meta",
      "product": "Meta Accounts Center, Instagram and Facebook SMS verification",
      "researchers": [
        "Gtm Mänôz"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "security-token-design",
        "authorization-modeling",
        "integration-threat-modeling"
      ],
      "summary": "Meta confirms a USD 27,200 total award for this account-verification report.",
      "root_cause": "Insufficient verification-attempt limits undermined phone ownership checks, while linked-account state changes could affect an existing SMS authentication factor.",
      "impact": "The vendor confirms possible SMS-based two-factor authentication bypass. The researcher demonstrated factor revocation; this alone does not establish password disclosure or an authenticated session.",
      "defensive_takeaways": [
        "Enforce verification-attempt limits consistently across linked applications.",
        "Require verified ownership before changing another account’s recovery or second-factor state."
      ],
      "reward": {
        "amount": 27200,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Meta",
        "evidence_level": "vendor_confirmed",
        "source_id": "vendor-retrospective",
        "evidence_quote": "We awarded a $27,200 bounty for this report.",
        "evidence_location": "Bug Highlights, 2FA Bypass paragraph naming Gtm Mänôz",
        "usd_equivalent": null,
        "notes": "Vendor total for one report. Researcher describes an initial September award and a December adjustment; component amounts are unknown and are not added on top. USD is contextualized by earlier official program reporting; settlement is unverified."
      },
      "dates": {
        "published": {
          "value": "2023-01-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Primary technical article date; distinct from the earlier vendor summary."
        },
        "public_disclosure": {
          "value": "2022-12-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-retrospective",
          "note": "Vendor’s high-level public summary. Researcher confirms this same-day highlight; a 2024 update concerns another case."
        },
        "reported": {
          "value": "2022-09-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": "2022-12-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Final additional award; initial amount was awarded September 24, 2022."
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Researcher received fix confirmation October 17, 2022; exact deployment date is not established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2022-12-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-retrospective",
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical technical publication in January 2023, describing a 2022 report."
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://medium.com/pentesternepal/two-factor-authentication-bypass-on-facebook-3f4ac3ea139c",
          "title": "Two Factor Authentication Bypass On Facebook",
          "type": "researcher",
          "author": "Gtm Mänôz",
          "retrieved_at": "2026-10-02T19:03:00Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "vendor-retrospective",
          "url": "https://about.fb.com/news/2022/12/metas-bug-bounty-program-2022/",
          "title": "Looking Back at Our Bug Bounty Program in 2022",
          "type": "vendor",
          "author": "Neta Oren / Meta",
          "retrieved_at": "2026-10-02T19:03:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Facebook Bug Bounty and BountyCon US-dollar reporting",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-02T18:24:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T19:03:00Z",
        "method": "Matched the researcher’s explicit vendor-retrospective link, name and account-verification issue to Meta’s per-report award. Retained final reward adjustment separately from cash settlement and fix confirmation.",
        "limitations": [
          "Exact reward-component amounts and cash-transfer date are unknown.",
          "Fix-confirmation date does not prove an exact deployment date.",
          "USD notation uses earlier official program context."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-pixel-lock-screen-state-binding-2022",
      "title": "Pixel lock-screen completion lost security-state binding",
      "organization": "Google",
      "product": "Google Pixel / Android lock-screen state management",
      "researchers": [
        "David Schütz"
      ],
      "cve_ids": [
        "CVE-2022-20465"
      ],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "client-security",
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "concurrency-reasoning",
        "approval-state-integrity",
        "patch-verification"
      ],
      "summary": "A researcher-published vendor decision documents a USD 70,000 award for CVE-2022-20465.",
      "root_cause": "The researcher’s patch analysis attributes the issue to completion events dismissing a different active security challenge after concurrent state changes.",
      "impact": "Physical access could bypass the lock screen on tested Pixel 5 and 6 devices. Broader Android coverage was not established by the researcher.",
      "defensive_takeaways": [
        "Bind authentication completion to the exact challenge and security context it satisfies.",
        "Model concurrent authentication-state transitions and reject stale completion events.",
        "Distinguish a security patch-level label from the date an update reached devices."
      ],
      "reward": {
        "amount": 70000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "Google Android Security Rewards",
        "status": "awarded",
        "evidence_level": "researcher_reported_with_vendor_quote",
        "source_id": "report-transcript",
        "evidence_quote": "we are happy to reward you the full amount of $70,000 USD",
        "evidence_location": "Reproduced vendor response dated October 12, 2022",
        "usd_equivalent": null,
        "notes": "Explicit USD decision for this report. It was initially marked duplicate; the reproduced response explains an exception because the report enabled remediation. Cash receipt is not separately documented."
      },
      "dates": {
        "published": {
          "value": "2022-11-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": "2022-11-08",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-cna",
          "note": "CVE record publication. The Android bulletin is dated November 7; its original snapshot was not retrieved, so first appearance of this entry is not asserted."
        },
        "reported": {
          "value": "2022-06-13",
          "precision": "day",
          "basis": "explicit",
          "source_id": "report-transcript",
          "note": null
        },
        "awarded": {
          "value": "2022-10-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "report-transcript",
          "note": null
        },
        "fixed": {
          "value": "2022-11",
          "precision": "month",
          "basis": "explicit",
          "source_id": "report-transcript",
          "note": "Reported fixed in the November update. The 2022-11-05 patch-level label is not used as an exact rollout date."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical primary publication outside the preferred last-12-month window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/",
          "title": "Accidental $70k Google Pixel Lock Screen Bypass",
          "type": "researcher",
          "author": "David Schütz",
          "retrieved_at": "2026-10-02T17:12:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "report-transcript",
          "url": "https://feed.bugs.xdavidhu.me/bugs/0016",
          "title": "Report 0016: Complete Lock Screen Bypass on Google Pixel devices",
          "type": "researcher",
          "author": "David Schütz",
          "retrieved_at": "2026-10-02T17:12:00Z",
          "supports": [
            "reward",
            "dates",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "android-bulletin",
          "url": "https://source.android.com/docs/security/bulletin/2022-11-01",
          "title": "Android Security Bulletin, November 2022",
          "type": "vendor",
          "author": "Android Open Source Project / Google",
          "retrieved_at": "2026-10-02T17:12:00Z",
          "supports": [
            "dates",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "pixel-bulletin",
          "url": "https://source.android.com/docs/security/bulletin/pixel/2022-11-01",
          "title": "Pixel Update Bulletin, November 2022",
          "type": "vendor",
          "author": "Google",
          "retrieved_at": "2026-10-02T17:12:00Z",
          "supports": [
            "dates",
            "remediation"
          ]
        },
        {
          "id": "vendor-cna",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2022/20xxx/CVE-2022-20465.json",
          "title": "Google Android CNA record for CVE-2022-20465",
          "type": "vendor",
          "author": "Google Android CNA, distributed through the CVE Program",
          "retrieved_at": "2026-10-02T17:14:30Z",
          "supports": [
            "dates",
            "root_cause",
            "impact",
            "cve"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T17:14:30Z",
        "method": "Read the researcher article, full reproduced report discussion and vendor bulletins; checked the explicit award decision and unique CVE. Cross-checked the Google-authored CNA record publication date.",
        "limitations": [
          "The award decision is reproduced by the researcher, not independently published by the vendor.",
          "Payment completion is unverified.",
          "Vendor patch-level labels and bulletin publication dates do not establish each device’s update deployment date."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "instagram-application-credential-client-containment-2022",
      "title": "Instagram client configuration exposed an application credential",
      "organization": "Meta",
      "product": "Instagram server-driven client interface",
      "researchers": [
        "Philippe Harewood"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "information-exposure",
      "secondary_category_ids": [
        "authorization",
        "client-security"
      ],
      "skillset_ids": [
        "secrets-containment",
        "machine-identity-governance",
        "authorization-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "Meta confirmed a $30,000 base award for an Instagram application-token exposure; additional researcher-listed bonuses are excluded from the recorded amount.",
      "root_cause": "Server-delivered interface configuration exposed an application credential to a client. The researcher distinguished application-level authority from ordinary client-token authority, identifying a mismatch between the data needed for rendering and the privilege carried by an embedded credential.",
      "impact": "The researcher reports retrieving application-role metadata. Meta confirms credential exposure but says independent protections limited further impact and it found no evidence of abuse. Unrestricted administration, account takeover and actual customer compromise were not established.",
      "defensive_takeaways": [
        "Classify every credential by its authority and intended holder before deciding whether it belongs in client-visible data.",
        "Keep privileged application credentials inside controlled server contexts; minimize the capabilities available to client integrations.",
        "Preserve independent authorization checks after credential validation, and distinguish the demonstrated exposure from hypothetical downstream consequences.",
        "Treat containment and least-privilege recommendations as design guidance; the sources do not document the complete vendor patch."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "evidence_level": "vendor_confirmed",
        "source_id": "vendor-bulletin",
        "evidence_quote": "awarded Harewood a $30,000 bounty award",
        "evidence_location": "Bug bounty work, paragraph about Philippe Harewood",
        "usd_equivalent": null,
        "notes": "Records the vendor-confirmed base once. The researcher separately lists $6,000 league, $2,250 delay and $50 event bonuses; these are not added to this amount or counted as separate findings. USD uses earlier official program denomination context; settlement is unknown.",
        "type": "bug_bounty",
        "awarding_organization": "Meta"
      },
      "dates": {
        "published": {
          "value": "2022-07-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-bulletin",
          "note": "Dated vendor publication is used. The researcher page presents February 24, 2022 and August 27, 2024 without a clearly extracted original-versus-update label; its original public release remains uncertain."
        },
        "public_disclosure": {
          "value": "2022-07-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-bulletin",
          "note": "Vendor discussion and direct researcher link establish public availability by this date, not the earliest possible disclosure."
        },
        "reported": {
          "value": "2022-02-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": "2022-05-19",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The researcher records fix confirmation on February 24, 2022 and removal within hours. The exact deployment date is not independently established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": "2022-07-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-bulletin",
          "note": "Public vendor confirmation; an earlier researcher announcement is possible."
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical vendor publication; no recency claim is based on the researcher page’s later date."
      },
      "sources": [
        {
          "id": "vendor-bulletin",
          "url": "https://engineering.fb.com/2022/07/20/security/how-meta-and-the-security-industry-collaborate-to-secure-the-internet/",
          "title": "How Meta and the security industry collaborate to secure the internet",
          "type": "vendor",
          "author": "Meta Engineering",
          "retrieved_at": "2026-10-02T20:20:00Z",
          "supports": [
            "reward",
            "dates",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "researcher-writeup",
          "url": "https://philippeharewood.com/instagram-app-access-token/",
          "title": "Instagram App Access Token",
          "type": "researcher",
          "author": "Philippe Harewood",
          "retrieved_at": "2026-10-02T20:20:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Facebook Bug Bounty and BountyCon US-dollar reporting",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-02T20:20:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "vendor-bulletin",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T20:20:00Z",
        "method": "Matched Meta’s named researcher and report-specific award to its directly linked technical article. Separated credential exposure, observed metadata access and vendor-stated containment.",
        "limitations": [
          "The vendor confirms the base; bonus breakdown and report/award timeline are researcher-reported.",
          "Original researcher publication and exact fix deployment are uncertain; the vendor bulletin supplies the publication date used here.",
          "The currency reference is older program context, not a report-specific settlement record.",
          "No full patch implementation or unrestricted downstream compromise is established."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "github-actions-reference-validation-2021",
      "title": "GitHub Actions trust depended on invalid repository references",
      "organization": "GitHub",
      "product": "GitHub Actions and GitHub Enterprise Server",
      "researchers": [
        "Teddy Katz"
      ],
      "cve_ids": [
        "CVE-2021-22862"
      ],
      "cwe_mappings": [],
      "category_id": "supply-chain",
      "secondary_category_ids": [
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "pipeline-trust-modeling",
        "authorization-modeling",
        "secrets-containment",
        "defensive-evidence-writing"
      ],
      "summary": "A reference-validation flaw crossed the GitHub Actions trust boundary and earned USD 25,000.",
      "root_cause": "Object validation differed between creation and mutation; automation relied on a branch-type invariant that was not consistently enforced.",
      "impact": "Repository secrets and write authority could become available to an unauthorized workflow.",
      "defensive_takeaways": [
        "Enforce security invariants at every mutation and at their privileged consumers.",
        "Keep repository secrets confined to explicitly trusted execution contexts."
      ],
      "reward": {
        "amount": 25000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "GitHub",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "GitHub awarded a $25000 bug bounty",
        "evidence_location": "Timeline, March 3, 2021",
        "usd_equivalent": null,
        "notes": "Single finding; the later 2022 follow-up earned USD 7,500 and is excluded."
      },
      "dates": {
        "published": {
          "value": "2021-03-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2021-02-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2021-03-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": "2021-03-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "GitHub Enterprise Server 3.0.1 release; github.com was fixed earlier in February, without an exact final timestamp in the source."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://blog.teddykatz.com/2021/03/17/github-actions-write-access.html",
          "title": "Stealing arbitrary GitHub Actions secrets",
          "type": "researcher",
          "author": "Teddy Katz",
          "retrieved_at": "2026-10-02T14:39:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T14:39:00Z",
        "method": "Primary public source read; individual award and source provenance verified. No target testing or exploit reproduction performed.",
        "limitations": [
          "Award is reported by the cited source; cash settlement is not independently audited."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.1.0",
      "id": "github-fork-collaboration-consent-2021",
      "title": "GitHub GraphQL collaboration changes lacked author consent",
      "organization": "GitHub",
      "product": "GitHub fork collaboration / GraphQL",
      "researchers": [
        "Teddy Katz"
      ],
      "cve_ids": [
        "CVE-2021-22863"
      ],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "approval-state-integrity",
        "defensive-evidence-writing"
      ],
      "summary": "The second fork-collaboration report received its own USD 10,000 award.",
      "root_cause": "One API path omitted the pull-request-author entitlement required to change collaboration consent.",
      "impact": "A base-repository maintainer could gain unauthorized write access to a contributor branch.",
      "defensive_takeaways": [
        "Keep collaboration consent separate from ordinary metadata privileges.",
        "Enforce identical ownership rules across API implementations."
      ],
      "reward": {
        "amount": 10000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "GitHub",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "GitHub awarded a $10000 bounty for the second issue",
        "evidence_location": "Timeline, March 2, 2021, 22:26:36 UTC",
        "usd_equivalent": null,
        "notes": "Separate report and award, initially marked duplicate then reopened after its distinct fix requirement was confirmed."
      },
      "dates": {
        "published": {
          "value": "2021-03-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2021-01-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2021-03-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": "2021-01-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "github.com deployment; Enterprise Server releases followed March 2, 2021."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://blog.teddykatz.com/2021/03/10/fork-collab-abuse.html",
          "title": "Messing with GitHub’s fork collaboration for fun and profit",
          "type": "researcher",
          "author": "Teddy Katz",
          "retrieved_at": "2026-10-02T15:12:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor-release",
          "url": "https://docs.github.com/en/enterprise-server@3.0/admin/release-notes",
          "title": "GitHub Enterprise Server 3.0.1 security fixes",
          "type": "vendor",
          "author": "GitHub",
          "retrieved_at": "2026-10-02T15:12:00Z",
          "supports": [
            "cve",
            "root_cause",
            "impact",
            "remediation",
            "dates"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T15:12:00Z",
        "method": "Primary public source read; individual award and source provenance verified. No target testing or exploit reproduction performed.",
        "limitations": [
          "Award remains researcher-reported; vendor release notes corroborate the distinct CVE and remediation."
        ]
      },
      "content_scope": "historical_defensive_summary",
      "report_identity": {
        "kind": "cve",
        "value": "CVE-2021-22863",
        "source_id": "primary",
        "evidence_location": "Timeline identifies the second issue as CVE-2021-22863 and assigns its own award."
      }
    },
    {
      "schema_version": "1.1.0",
      "id": "github-fork-collaboration-authorization-2021",
      "title": "GitHub fork collaboration applied inconsistent authorization",
      "organization": "GitHub",
      "product": "GitHub fork collaboration",
      "researchers": [
        "Teddy Katz"
      ],
      "cve_ids": [
        "CVE-2021-22861"
      ],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "approval-state-integrity",
        "defensive-evidence-writing"
      ],
      "summary": "The first fork-collaboration finding in this article earned USD 20,000.",
      "root_cause": "Permission checks differed between creation and modification of the same collaboration setting.",
      "impact": "An unauthorized user could obtain write access to affected public forks.",
      "defensive_takeaways": [
        "Centralize entitlement checks across mutation paths.",
        "Verify that only an authorized owner can grant collaboration privileges."
      ],
      "reward": {
        "amount": 20000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "GitHub",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "GitHub awarded a $20000 bounty for the first issue",
        "evidence_location": "Timeline, March 2, 2021",
        "usd_equivalent": null,
        "notes": "First report only; the separately awarded CVE-2021-22863 is a different record."
      },
      "dates": {
        "published": {
          "value": "2021-03-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2021-01-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2021-03-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": "2021-01-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "github.com deployment; Enterprise Server releases followed March 2, 2021."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://blog.teddykatz.com/2021/03/10/fork-collab-abuse.html",
          "title": "Messing with GitHub’s fork collaboration for fun and profit",
          "type": "researcher",
          "author": "Teddy Katz",
          "retrieved_at": "2026-10-02T15:12:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T15:12:00Z",
        "method": "Primary public source read; individual award and source provenance verified. No target testing or exploit reproduction performed.",
        "limitations": [
          "Award is reported by the cited source; cash settlement is not independently audited."
        ]
      },
      "content_scope": "historical_defensive_summary",
      "report_identity": {
        "kind": "cve",
        "value": "CVE-2021-22861",
        "source_id": "primary",
        "evidence_location": "Timeline identifies the first issue as CVE-2021-22861 and assigns its own award."
      }
    },
    {
      "schema_version": "1.0.0",
      "id": "microsoft-account-recovery-rate-limit-consistency-2021",
      "title": "Microsoft account recovery lacked consistent attempt-limit enforcement",
      "organization": "Microsoft",
      "product": "Microsoft account recovery",
      "researchers": [
        "Laxman Muthiyah"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "concurrency-reasoning",
        "authorization-modeling"
      ],
      "summary": "The cited researcher documents a USD 50,000 award for this finding.",
      "root_cause": "Recovery controls did not enforce attempt limits consistently across simultaneous verification operations. Defensive reviews should verify atomic, account-bound limits and consistent treatment of recovery and multifactor checks.",
      "impact": "Potential account takeover; the researcher says Microsoft classified severity as Important because practical exploitation required substantial resources.",
      "defensive_takeaways": [
        "Bind recovery attempts and verification state to the intended account.",
        "Use atomic security counters and test concurrent state transitions locally."
      ],
      "reward": {
        "amount": 50000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "Microsoft",
        "status": "paid",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "I received the bounty of $50,000 USD on Feb 9th, 2021 through hackerone",
        "evidence_location": "Primary article award statement",
        "usd_equivalent": null,
        "notes": "Researcher says the bounty was received on February 9, 2021; that is the payment date, not a separately confirmed award-decision date."
      },
      "dates": {
        "published": {
          "value": "2021-03-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "source-2",
          "note": "Original publication date preserved by the author’s archive; current article header is a later update."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": "2020-11",
          "precision": "month",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "paid": {
          "value": "2021-02-09",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical primary publication, outside the preferred last-12-month window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://thezerohack.com/how-i-might-have-hacked-any-microsoft-account",
          "title": "Microsoft account recovery lacked consistent attempt-limit enforcement",
          "type": "researcher",
          "author": "Laxman Muthiyah",
          "retrieved_at": "2026-10-02T14:43:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "source-2",
          "url": "https://thezerohack.com/digital-marketing",
          "title": "Original publication archive",
          "type": "researcher",
          "author": "Laxman Muthiyah",
          "retrieved_at": "2026-10-02T14:43:00Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T14:43:00Z",
        "method": "Primary public sources read; individual reward, dates, and attribution reviewed. No target testing performed.",
        "limitations": [
          "The article header now shows a 2024 update; its archive preserves March 2, 2021 publication",
          "No independent vendor-hosted payout confirmation retrieved",
          "Current article update: 2024-12-06; original publication is stored separately."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "apple-sign-in-identity-claim-binding-2020",
      "title": "Sign in with Apple failed to bind identity claims to the authenticated user",
      "organization": "Apple",
      "product": "Sign in with Apple",
      "researchers": [
        "Bhavuk Jain"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [],
      "skillset_ids": [
        "identity-lifecycle-review",
        "authorization-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "Bhavuk Jain reports being paid $100,000 for this finding. The recorded USD denomination is a contextual inference from Apple's May 2019 program documentation, published about one year before the May 2020 disclosure.",
      "root_cause": "Token issuance failed to maintain a trustworthy relationship between the authenticated identity and identity claims used by relying applications. Cryptographic validity alone did not establish correct claim ownership.",
      "impact": "Potential takeover of third-party application accounts using the integration without additional safeguards. Named third-party applications were not tested by the researcher.",
      "defensive_takeaways": [
        "Validate identity-claim ownership in addition to token cryptographic validity.",
        "Document relying-party assumptions and additional authentication safeguards."
      ],
      "reward": {
        "amount": 100000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "Apple",
        "status": "paid",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "For this vulnerability, I was paid $100,000 by Apple under their Apple Security Bounty program.",
        "evidence_location": "Primary article award statement",
        "usd_equivalent": null,
        "notes": "The researcher explicitly reports being paid $100,000 but supplies no currency code or exact settlement date. USD is contextually inferred from Apple's May 2019 iOS Security guide (currency-context), whose Apple Security Bounty table on printed page 87 labels maximum payments in USD. This source describes the then-existing iOS program and predates the May 2020 disclosure by about one year. It supplies denomination context only and does not independently establish this individual payment's currency, amount, category or settlement."
      },
      "dates": {
        "published": {
          "value": "2020-05-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical primary publication, outside the preferred last-12-month window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-apple/",
          "title": "Sign in with Apple failed to bind identity claims to the authenticated user",
          "type": "researcher",
          "author": "Bhavuk Jain",
          "retrieved_at": "2026-10-04T14:42:20Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.apple.com/jp/business/site/docs/site/iOS_Security_Guide.pdf",
          "title": "iOS Security, iOS 12.3, May 2019, printed page 87: denomination context only",
          "type": "vendor",
          "author": "Apple",
          "retrieved_at": "2026-10-04T14:42:30Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-04T14:44:04Z",
        "method": "Primary researcher payment statement reread; Apple's May 2019 iOS Security guide reviewed for earlier program-level denomination context only. Individual payment attribution remains researcher-reported. No target testing performed.",
        "limitations": [
          "No exact report, fix, or payment date stated",
          "Researcher says Apple's investigation found no misuse; independent vendor payout confirmation was not retrieved",
          "USD is inferred from earlier program-level context, not explicitly stated in the individual payment report. The May 2019 guide does not establish the payment's category or the program wording at payment time. No conflicting denomination was identified in the reviewed sources."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "facebook-error-response-data-isolation-2019",
      "title": "Facebook error responses exposed unintended application data",
      "organization": "Meta (Facebook)",
      "product": "Facebook copyright-management endpoint and shared error handling",
      "researchers": [
        "Youssef Sammouda"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "information-exposure",
      "secondary_category_ids": [],
      "skillset_ids": [
        "error-response-design",
        "secure-parser-review",
        "defensive-evidence-writing",
        "patch-verification"
      ],
      "summary": "Facebook confirms a USD 65,000 bounty payment for an error-response data-exposure report.",
      "root_cause": "An error-handling configuration could include unintended application data in a response; subsequent review found a broader framework issue.",
      "impact": "A copyright-management request could return data fragments not intended for the requester. The award reflected the vendor’s assessment of potential wider impact.",
      "defensive_takeaways": [
        "Apply data-minimization rules to error responses as well as successful responses.",
        "Review shared exception-handling behavior after an endpoint-level fix."
      ],
      "reward": {
        "amount": 65000,
        "currency": "USD",
        "scope": "single_report",
        "status": "paid",
        "type": "bug_bounty",
        "awarding_organization": "Meta",
        "evidence_level": "vendor_confirmed",
        "source_id": "vendor-retrospective",
        "evidence_quote": "Su pago por recompensa equivalente a USD$ 65,000",
        "evidence_location": "Identificación de errores, Youssef Sammouda finding",
        "usd_equivalent": null,
        "notes": "Vendor explicitly identifies USD and says the report was paid. Exact transfer date is unknown; this is not the event or program total."
      },
      "dates": {
        "published": {
          "value": "2020-02-07",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor-retrospective",
          "note": "Initial page date; a separate May 7, 2020 update is displayed."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The reviewed vendor retrospective was published February 7, 2020; earliest public disclosure is not established."
        },
        "reported": {
          "value": "2019-09",
          "precision": "month",
          "basis": "inferred",
          "source_id": "vendor-retrospective",
          "note": "September event in the vendor’s 2019 retrospective; the day is unspecified."
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Vendor states an initial fix followed within hours of the report, then broader framework remediation; exact deployment dates are not supplied."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Vendor confirms payment but gives no transfer date."
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical 2019 finding, described by the vendor in February 2020."
      },
      "sources": [
        {
          "id": "vendor-retrospective",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "2019 Bug Bounty highlights, official Spanish edition",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-02T18:24:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "vendor-retrospective",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T18:24:00Z",
        "method": "Read the official vendor retrospective and its explicit US-dollar per-report payment. Summaries retain the vendor’s bounded impact statement.",
        "limitations": [
          "Historical case; exact award, settlement and deployment dates are unknown.",
          "The source gives a high-level finding, not a complete technical advisory."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "github-oauth-method-semantics-2019",
      "title": "GitHub OAuth consent failed across request-method semantics",
      "organization": "GitHub",
      "product": "GitHub OAuth authorization",
      "researchers": [
        "Teddy Katz"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "authentication",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "identity-lifecycle-review",
        "secure-parser-review",
        "approval-state-integrity"
      ],
      "summary": "A USD 25,000 researcher-reported award illustrates how differing framework and controller assumptions can remove an OAuth consent boundary.",
      "root_cause": "The researcher compared the consent screen’s intended state change with routing and controller logic. The framework accepted a wider set of request semantics than the controller expected. Application logic treated the unexpected case as permission to grant access, even though the usual consent safeguards did not apply. The failed invariant was that every new grant required the user’s explicit, validated approval.",
      "impact": "The researcher reports that a user visiting a malicious website could unintentionally grant an application access to read or modify private GitHub data. This demonstrates unauthorized delegated access, rather than evidence that the attacker learned the account password or that all unrelated account controls failed.",
      "defensive_takeaways": [
        "Require positive validation of the intended state-changing operation; reject unrecognized alternatives rather than defaulting to a privileged action.",
        "Model framework routing, request interpretation and consent enforcement as separate layers whose assumptions must agree.",
        "Verify that consent and request-integrity checks remain attached to every path that creates a grant.",
        "The source dates the production fix and later Enterprise releases, but does not document the exact patch here; these lessons are defensive recommendations."
      ],
      "reward": {
        "amount": 25000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "GitHub",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "GitHub awards $25000 bounty",
        "evidence_location": "Timeline, June 26, 2019",
        "usd_equivalent": null,
        "notes": "Individual report; production fix date is for github.com, with enterprise releases following June 26."
      },
      "dates": {
        "published": {
          "value": "2019-11-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2019-06-19",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2019-06-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": "2019-06-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://blog.teddykatz.com/2019/11/05/github-oauth-bypass.html",
          "title": "Bypassing GitHub’s OAuth flow",
          "type": "researcher",
          "author": "Teddy Katz",
          "retrieved_at": "2026-10-02T19:39:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T19:39:00Z",
        "method": "Re-read the researcher’s intended-consent model, framework/controller distinction, impact and remediation timeline. Expanded the original explanation while omitting the triggering request and reproduction details.",
        "limitations": [
          "Researcher-reported award; cash settlement is not independently audited.",
          "The reported impact requires user interaction. Exact vendor patch implementation and evidence of real-world abuse are not supplied."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "instagram-recovery-challenge-account-binding-2019",
      "title": "Instagram recovery challenges were insufficiently bound to accounts",
      "organization": "Facebook / Instagram",
      "product": "Instagram account recovery",
      "researchers": [
        "Laxman Muthiyah"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "concurrency-reasoning",
        "authorization-modeling"
      ],
      "summary": "The researcher reports a $10,000 award for this finding. USD is a contextual currency inference from Facebook’s later official retrospective of its 2019 bounty program, not an explicit denomination in the individual award statement.",
      "root_cause": "Recovery challenge state did not maintain sufficiently strict binding among account, device context, and verification secret. Review challenge ownership and uniqueness throughout the recovery lifecycle.",
      "impact": "Researcher reports a separate, lower-severity account-takeover finding, fixed before publication.",
      "defensive_takeaways": [
        "Bind recovery attempts and verification state to the intended account.",
        "Use atomic security counters and test concurrent state transitions locally."
      ],
      "reward": {
        "amount": 10000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "Facebook / Instagram",
        "status": "awarded",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty program.",
        "evidence_location": "Primary article award statement",
        "usd_equivalent": null,
        "notes": "Individual finding, distinct from the researcher’s other Instagram recovery report; no additional bonus is counted. The primary article states $10000 without naming the currency. USD is a contextual inference from source-3, Facebook’s official 2019 program retrospective published February 7, 2020, roughly six months after the August 25, 2019 original article publication. The retrospective reports program-wide amounts in USD; it does not independently establish the denomination or settlement of this individual award. Exact award/payment dates remain unknown."
      },
      "dates": {
        "published": {
          "value": "2019-08-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "source-2",
          "note": "Original publication date preserved by the author’s archive; current article header is a later update."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical primary publication, outside the preferred last-12-month window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://thezerohack.com/hack-instagram-again",
          "title": "Instagram recovery challenges were insufficiently bound to accounts",
          "type": "researcher",
          "author": "Laxman Muthiyah",
          "retrieved_at": "2026-10-03T23:51:11Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "source-2",
          "url": "https://thezerohack.com/digital-marketing",
          "title": "Original publication archive",
          "type": "researcher",
          "author": "Laxman Muthiyah",
          "retrieved_at": "2026-10-02T14:43:00Z",
          "supports": [
            "dates"
          ]
        },
        {
          "id": "source-3",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Facebook 2019 Bug Bounty retrospective — contextual USD denomination only",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-03T23:50:58Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T23:53:25Z",
        "method": "Re-read the primary article award statement and Facebook’s official 2019 program retrospective for contextual currency evidence. Existing publication chronology retained. No target testing performed.",
        "limitations": [
          "The current 2024 article header is not the original disclosure date",
          "Exact report, fix, and award dates are unavailable",
          "No independent vendor-hosted payout confirmation retrieved",
          "Current article update: 2024-12-06; original publication is stored separately.",
          "USD is inferred from later program-wide context (source-3), not explicitly stated by the individual award source; neither individual denomination nor cash settlement is independently confirmed."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "instagram-mobile-recovery-attempt-limits-2019",
      "title": "Instagram mobile account recovery had inconsistent verification limits",
      "organization": "Facebook / Instagram",
      "product": "Instagram account recovery",
      "researchers": [
        "Laxman Muthiyah"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "concurrency-reasoning",
        "authorization-modeling"
      ],
      "summary": "The cited researcher documents a USD 30,000 award for this finding.",
      "root_cause": "Account recovery relied on verification limits that did not provide a consistent account-level security boundary under concurrent activity. Centralized, atomic attempt accounting is the defensive concern.",
      "impact": "The researcher demonstrated unauthorized password reset and reports remediation before publication.",
      "defensive_takeaways": [
        "Bind recovery attempts and verification state to the intended account.",
        "Use atomic security counters and test concurrent state transitions locally."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "Facebook / Instagram",
        "status": "awarded",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "Facebook and Instagram security team fixed the issue and rewarded me $30000 as a part of their bounty program.",
        "evidence_location": "Primary article award statement",
        "usd_equivalent": null,
        "notes": "Individual finding, distinct from the researcher’s other Instagram recovery report; exact award/payment dates are unknown."
      },
      "dates": {
        "published": {
          "value": "2019-07-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "source-2",
          "note": "Original publication date preserved by the author’s archive; current article header is a later update."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical primary publication, outside the preferred last-12-month window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://thezerohack.com/hack-any-instagram",
          "title": "Instagram mobile account recovery had inconsistent verification limits",
          "type": "researcher",
          "author": "Laxman Muthiyah",
          "retrieved_at": "2026-10-02T14:43:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "source-2",
          "url": "https://thezerohack.com/digital-marketing",
          "title": "Original publication archive",
          "type": "researcher",
          "author": "Laxman Muthiyah",
          "retrieved_at": "2026-10-02T14:43:00Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T14:43:00Z",
        "method": "Primary public sources read; individual reward, dates, and attribution reviewed. No target testing performed.",
        "limitations": [
          "The current 2024 article header is not the original disclosure date",
          "Exact report, fix, and award dates are unavailable",
          "Distinct from the August 2019 device-binding report",
          "Current article update: 2024-10-19; original publication is stored separately."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "shopify-exchange-request-isolation-2019",
      "title": "Shopify Exchange screenshot service crossed internal boundaries",
      "organization": "Shopify",
      "product": "Shopify Exchange screenshot service",
      "researchers": [
        "0xacb"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "server-request-trust",
      "secondary_category_ids": [
        "cloud-security"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "cloud-iam-review",
        "secrets-containment",
        "defensive-evidence-writing"
      ],
      "summary": "Shopify awarded USD 25,000 for a screenshot-service request-isolation flaw with impact bounded to one infrastructure subset.",
      "root_cause": "Server-side fetching crossed the boundary between externally influenced screenshot work and internal infrastructure. The vendor’s remediation targeted metadata access and internal destinations; its retrospective omits authentication prerequisites and the researcher’s reasoning process.",
      "impact": "Shopify confirms reported root-access capability across containers in the affected subset, explicitly excluding Shopify core. The retrospective does not establish compromise of every container or quantify exposed data. The service was disabled within an hour; infrastructure review preceded metadata shielding and internal-address restrictions.",
      "defensive_takeaways": [
        "Editorial lesson: separately enforce request-destination policy, workload privilege and infrastructure segmentation; each limits a different boundary.",
        "Editorial lesson: treat metadata as privileged infrastructure data and deny unneeded service access.",
        "Editorial lesson: preserve the distinction between a demonstrated access capability and a claim of widespread compromise."
      ],
      "reward": {
        "amount": 25000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Shopify",
        "evidence_level": "vendor_confirmed",
        "source_id": "primary",
        "evidence_quote": "SSRF in Exchange leads to ROOT access in all instances - Bounty: $25,000",
        "evidence_location": "Top Three Interesting Bugs, first entry",
        "usd_equivalent": null,
        "notes": "Vendor retrospective explicitly ties this amount to one report. Original report, award, and fix dates are not supplied."
      },
      "dates": {
        "published": {
          "value": "2019-04-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://shopify.engineering/one-million-dollars-in-bug-bounties",
          "title": "One Million Dollars in Bug Bounties",
          "type": "vendor",
          "author": "Peter Yaworski / Shopify",
          "retrieved_at": "2026-10-02T23:00:55Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T23:00:55Z",
        "method": "Reread the vendor retrospective, including its impact boundary and remediation account. No target testing.",
        "limitations": [
          "The publication date is retrospective, not the original discovery date.",
          "Underlying report details were not independently reread; no additional exploit prerequisites or investigative chronology are asserted."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "shopify-collaborator-conversion-consent-2017",
      "title": "Shopify automatic account conversion lost merchant-consent binding",
      "organization": "Shopify",
      "product": "Shopify partner collaborator accounts",
      "researchers": [
        "uzsunny"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "authentication",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "identity-lifecycle-review",
        "defensive-evidence-writing"
      ],
      "summary": "Shopify confirms a $20,000 award for unauthorized collaborator access caused by automatic account conversion.",
      "root_cause": "Account-conversion logic did not preserve the distinction between identity linkage and authorization to collaborate on a merchant’s store. The vendor attributes the issue to automatic conversion of ordinary accounts into collaborator accounts.",
      "impact": "The vendor confirms unintended store access without merchant interaction in a partner-account context, and says it fixed the issue within hours. Its retrospective does not establish data extraction, the exact permissions obtained or the researcher’s discovery process.",
      "defensive_takeaways": [
        "Editorial lesson: require an independently verified entitlement for each role transition; matching identity attributes do not prove resource access rights.",
        "Editorial lesson: preserve merchant approval when accounts are linked, merged or automatically converted.",
        "Editorial lesson: model authorization before and after lifecycle transitions, including repeated or conflicting identities, using approved test accounts."
      ],
      "reward": {
        "amount": 20000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "evidence_level": "vendor_confirmed",
        "source_id": "primary",
        "evidence_quote": "our highest payout to date awarded, $20,000 to uzsunny",
        "evidence_location": "Our Highest Payout to Date",
        "usd_equivalent": null,
        "notes": "One report, separate from event totals. USD is a contextual inference from HackerOne’s 2026 platform policy, nine years after the 2017 award; that policy does not prove settlement.",
        "type": "bug_bounty",
        "awarding_organization": "Shopify"
      },
      "dates": {
        "published": {
          "value": "2018-02-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "awarded": {
          "value": "2017",
          "precision": "year",
          "basis": "explicit",
          "source_id": "primary",
          "note": "The vendor identifies the award as occurring during 2017; no precise day is supplied."
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Vendor reports a fix within hours but supplies no calendar date in the reviewed retrospective."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical reference outside the preferred last-12-month publication window."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://shopify.engineering/bug-bounty-year-in-review",
          "title": "2017 Bug Bounty Year in Review",
          "type": "vendor",
          "author": "Peter Yaworski / Shopify",
          "retrieved_at": "2026-10-03T02:32:41Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "platform-currency",
          "url": "https://www.hackerone.com/terms/disclosure-guidelines",
          "title": "Vulnerability Disclosure Standards",
          "type": "platform",
          "author": "HackerOne",
          "retrieved_at": "2026-10-03T02:32:41Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T02:32:41Z",
        "method": "Read public primary-source text and checked award scope, provenance and dates. No target testing.",
        "limitations": [
          "The underlying linked HackerOne report was JavaScript-only in text retrieval and was not independently reviewed.",
          "Currency context is platform-wide and later than the award; no independent payment audit is claimed.",
          "No exact reporting, fix or payment date was established."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "hackerone-export-attachment-authorization-2016",
      "title": "HackerOne exports omitted internal-attachment authorization",
      "organization": "HackerOne",
      "product": "HackerOne report archive export",
      "researchers": [
        "japz (japzdivino)"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "information-exposure"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "defensive-evidence-writing",
        "secure-parser-review"
      ],
      "summary": "HackerOne awarded $12,500 for internal attachments exposed through report export in 2016. Its enduring lesson for 2026 applications is that export and interactive views must enforce the same visibility policy.",
      "root_cause": "Export authorization diverged from report-view visibility. A file moved into an internal comment remained exportable. The researcher compared redacted display content with archive output; the vendor confirmed this was a distinct newly introduced issue.",
      "impact": "A user able to export a report could obtain team-only attachments. Vendor review additionally identified potential inline-attachment exposure, but found no evidence of malicious exploitation. This does not establish access to every private report.",
      "defensive_takeaways": [
        "Derive export contents from the same object-level policy used for interactive views.",
        "Treat referenced attachments as independently authorized objects, including after visibility changes."
      ],
      "dates": {
        "published": {
          "value": "2016-11-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "public-report",
          "note": "Detailed report became public at the recorded disclosure event; later 2017 retrospective is not original publication."
        },
        "public_disclosure": {
          "value": "2016-11-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "public-report",
          "note": null
        },
        "reported": {
          "value": "2016-11-29",
          "precision": "day",
          "basis": "explicit",
          "source_id": "public-report",
          "note": null
        },
        "awarded": {
          "value": "2016-11-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "public-report",
          "note": null
        },
        "fixed": {
          "value": "2016-11-29",
          "precision": "day",
          "basis": "explicit",
          "source_id": "public-report",
          "note": "Vendor fix-release comment at 04:36 UTC; researcher confirmation at 05:02 UTC. Summary says November 28 without a timezone; UTC timeline supplies the recorded date."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical disclosure outside the preferred publication window."
      },
      "sources": [
        {
          "id": "public-report",
          "url": "https://hackerone.com/reports/186230",
          "title": "Internal attachments can be exported via \"Export as .zip\" feature",
          "type": "platform",
          "author": "HackerOne and japz",
          "retrieved_at": "2026-10-03T14:00:08Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "vendor-retrospective",
          "url": "https://www.hackerone.com/blog/celebrating-20m-bounties-recap-our-top-20-voted-reports-hacktivity",
          "title": "Celebrating $20M in Bounties with a Recap of Our Top 20 Up Voted Reports on Hacktivity",
          "type": "vendor",
          "author": "johnk / HackerOne",
          "retrieved_at": "2026-10-03T14:00:08Z",
          "supports": [
            "reward",
            "impact"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.hackerone.com/terms/disclosure-guidelines",
          "title": "Vulnerability Disclosure Guidelines",
          "type": "platform",
          "author": "HackerOne",
          "retrieved_at": "2026-10-03T14:00:08Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "public-report",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T14:00:08Z",
        "method": "Read the full public report in the cloud browser, including vendor summary, fix confirmation, award and disclosure timeline; corroborated award with the vendor retrospective. Reviewed currency guidance separately.",
        "limitations": [
          "No independent confirmation of cash settlement.",
          "Currency uses later platform-wide guidance, not an explicit currency code in the historical award event.",
          "Summary uses November 28 without timezone; the report and fix events display November 29 UTC.",
          "No patch implementation is disclosed."
        ]
      },
      "content_scope": "historical_defensive_summary",
      "reward": {
        "amount": 12500,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "HackerOne",
        "evidence_level": "platform_confirmed",
        "source_id": "public-report",
        "evidence_quote": "rewarded japz with a $12,500 bounty",
        "evidence_location": "November 30, 2016, 9:15am UTC award event; report sidebar",
        "usd_equivalent": null,
        "notes": "One report-level award includes the vendor’s expanded inline-attachment impact assessment. USD uses later platform-wide payment guidance reviewed in 2026, about ten years after the award; it does not prove individual settlement. The report explicitly distinguishes earlier report 182358."
      }
    },
    {
      "schema_version": "1.0.0",
      "id": "facebook-phone-linking-account-authorization-2013",
      "title": "Facebook phone linking lacked account-specific authorization",
      "organization": "Meta (Facebook)",
      "product": "Facebook phone linking and account recovery",
      "researchers": [
        "Jack Whitton"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "authentication"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "defensive-evidence-writing",
        "identity-lifecycle-review"
      ],
      "summary": "A 2013 researcher disclosure reports a $20,000 award for unauthorized recovery-phone binding. Its enduring lesson for 2026 applications is that recovery-factor possession and account-change authority require separate checks.",
      "root_cause": "Phone possession and requester reauthentication did not establish permission to change the selected account. The missing boundary was authorization over the account receiving a recovery factor.",
      "impact": "The researcher describes account takeover without victim interaction, requiring a researcher-controlled account and phone. The demonstrated flow reached password recovery; broader account coverage is the researcher’s claim.",
      "defensive_takeaways": [
        "Bind recovery-factor enrollment to the authenticated subject and authorized account.",
        "Possession of a new factor cannot substitute for authority over the account it will recover."
      ],
      "dates": {
        "published": {
          "value": "2013-06-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2013-05-23",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": "2013-05-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": false,
        "basis": "published",
        "note": "Historical disclosure outside the preferred publication window."
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://whitton.io/articles/hijacking-a-facebook-account-with-sms/",
          "title": "Hijacking a Facebook Account with SMS",
          "type": "researcher",
          "author": "Jack Whitton",
          "retrieved_at": "2026-10-03T14:00:08Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Facebook 2019 Bug Bounty retrospective, official Spanish edition",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-03T14:00:08Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T14:00:08Z",
        "method": "Read the original dated researcher article and its report-specific award statement. Reviewed later official denomination context separately.",
        "limitations": [
          "Exact award and payment dates are unknown; assigned does not establish paid.",
          "Currency is inferred from later official program context, not explicit in the individual award statement.",
          "Researcher reports the fix added account-specific permission validation; implementation and discovery history are not supplied."
        ]
      },
      "content_scope": "historical_defensive_summary",
      "reward": {
        "amount": 20000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Facebook",
        "evidence_level": "researcher_reported",
        "source_id": "researcher-writeup",
        "evidence_quote": "The bounty assigned to this bug was $20,000",
        "evidence_location": "Note section",
        "usd_equivalent": null,
        "notes": "The researcher states an assigned award, not a settlement. USD is a contextual inference from Facebook’s later official US-dollar program reporting in February 2020, nearly seven years after this disclosure; that source does not independently establish this award’s denomination or payment."
      }
    },
    {
      "schema_version": "1.0.0",
      "id": "meta-pixel-cross-window-authority-binding-2024",
      "title": "Meta Pixel cross-window handling lost message and token authority",
      "organization": "Meta",
      "product": "Meta Pixel and Instagram account integrations",
      "researchers": [
        "Youssef Sammouda"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "authentication",
        "client-security"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "identity-lifecycle-review",
        "integration-threat-modeling",
        "browser-isolation-review"
      ],
      "summary": "The USD 32,500 researcher-reported award illustrates the distinction between message origin and disclosure authority.",
      "root_cause": "The researcher followed how browser messages influenced requests containing page context. A trusted-origin check substituted for a complete authorization decision: the requested operation and recipient identity were not bound to the protected context. The failure allowed sensitive information to cross into a different identity’s request context.",
      "impact": "The researcher reports authorization-material exposure and consequent Instagram takeover with user interaction. Wider script deployment does not establish equivalent impact on every embedding site or evidence of real-world abuse.",
      "defensive_takeaways": [
        "Check the expected sender relationship and message structure, then independently authorize the requested operation and recipient.",
        "Define a minimal disclosure contract for analytics and integration messages; omit authentication artifacts from general page context.",
        "Review grant-to-client binding separately from message transport and preserve those distinctions in evidence.",
        "These are defensive recommendations; the precise vendor patch and the separately alleged grant-binding fix are not independently verified."
      ],
      "reward": {
        "amount": 32500,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Meta",
        "evidence_level": "researcher_reported",
        "source_id": "researcher-writeup",
        "evidence_quote": "$32,500 bounty awarded by Meta",
        "evidence_location": "Researcher timeline, dated award entry",
        "usd_equivalent": null,
        "notes": "One researcher-reported bug bounty, not an event total. The article uses $; prior official Meta program reporting supplies USD context. Actual cash settlement is not established."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Current archive page displays 2026-01-16. Original publication versus migration/republication is not established, so this date is not used as a recent disclosure."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Earliest public disclosure remains unverified; the current archive header does not resolve it."
        },
        "reported": {
          "value": "2024-10-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": "2025-02-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "fixed": {
          "value": "2024-10-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Overall fix date in the researcher timeline. A separately alleged, disputed grant-binding component has no confirmed fix date; this timestamp does not cover it."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": null,
        "basis": "published",
        "note": "Original publication is unknown; the January 2026 archive header is not counted as recent research. Report and award timelines remain separately dated."
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://ysamm.com/uncategorized/2026/01/16/leaking-fbevents-ato.html",
          "title": "Instagram account takeover via Meta Pixel script abuse",
          "type": "researcher",
          "author": "Youssef Sammouda",
          "retrieved_at": "2026-10-02T19:49:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Facebook Bug Bounty and BountyCon US-dollar reporting",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-02T18:24:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T19:49:00Z",
        "method": "Reviewed the primary explanation and timeline; clarified component-level uncertainty while preserving unknown original publication.",
        "limitations": [
          "Researcher-reported award; no independent vendor confirmation or audited transfer.",
          "January 2026 page dates may reflect publication or archive migration; original disclosure is not established.",
          "USD normalization uses earlier official program context rather than an award receipt.",
          "A separate grant-binding flaw is alleged and described as disputed; vendor confirmation and its precise fix date are unverified."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.2.0",
      "id": "meta-conversions-gateway-message-origin-boundary-2024",
      "title": "Meta Conversions API Gateway trusted message origins as script authority",
      "organization": "Meta",
      "product": "Conversions API Gateway",
      "researchers": [
        "Youssef Sammouda"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "client-security",
      "secondary_category_ids": [
        "injection"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "untrusted-input-handling",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "The researcher assigns a separate $62,500 award to the client-side finding labeled Bug #1.",
      "root_cause": "A browser message origin became trusted script-host configuration without origin authorization.",
      "impact": "The researcher reports script execution and describes possible account takeover. The scenario depends on specific embedded-browser, initialization and content-policy conditions plus influence over permitted third-party content. Account impact additionally assumes user interaction and an authenticated session; universal or interaction-free exploitation is not established.",
      "defensive_takeaways": [
        "Authorize message origins and senders independently of message content; treat an integration identifier as data rather than proof of authority.",
        "Keep script-source authority separate from mutable messaging configuration, and review it together with browser isolation and content policy.",
        "Define regression coverage for initialization state, embedded-browser behavior and third-party trust; distinguish observed execution from modeled account impact."
      ],
      "reward": {
        "amount": 62500,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Meta",
        "evidence_level": "researcher_reported",
        "source_id": "researcher-writeup",
        "evidence_quote": "$62,500 bounty awarded by Meta for Bug #1",
        "evidence_location": "Timeline, December 24, 2024 entry assigned to Bug #1",
        "usd_equivalent": null,
        "notes": "Separate from Bug #2; no aggregation. The dollar sign is interpreted as USD using official 2020 program context, nearly five years earlier. This does not establish individual settlement currency or payment."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Current header: January 13, 2026. Original publication is unestablished; archive dating cannot establish first disclosure."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Earliest public disclosure is not established."
        },
        "reported": {
          "value": "2024-11-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Explicit Timeline entry labeled Bug #1."
        },
        "awarded": {
          "value": "2024-12-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Explicit Timeline entry labeled Bug #1."
        },
        "fixed": {
          "value": "2024-12-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Explicit Timeline entry labeled Bug #1."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": null,
        "basis": "published",
        "note": "Original publication is unknown. The January 2026 archive header is not counted as a new disclosure."
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://ysamm.com/uncategorized/2026/01/13/capig-xss.html",
          "title": "Multiple XSS in Meta Conversion API Gateway Leading to Zero-Click Account Takeover",
          "type": "researcher",
          "author": "Youssef Sammouda",
          "retrieved_at": "2026-10-03T12:49:20Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "report_identity"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Facebook Bug Bounty and BountyCon US-dollar reporting",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-03T12:49:20Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T12:49:20Z",
        "method": "Freshly read the primary article and official denomination context; compared report boundaries against the existing backend record. No live testing.",
        "limitations": [
          "Researcher-reported award, not vendor-confirmed payment; settlement date remains unknown.",
          "USD is contextual inference with an almost five-year gap, not an individual receipt.",
          "Original publication and earliest disclosure remain unknown.",
          "The narrative puts Bug #2 after reporting Bug #1; the labeled timeline orders reports oppositely. Dates follow labels without reconciling the conflict.",
          "Execution is researcher-reported; completed account takeover, population-wide exposure and exact patch coverage are not independently established.",
          "The article-wide zero-click framing should not be generalized to this interaction-dependent finding."
        ]
      },
      "content_scope": "historical_defensive_summary",
      "report_identity": {
        "kind": "source_label",
        "value": "Bug #1",
        "source_id": "researcher-writeup",
        "evidence_location": "First bug heading; Timeline entries labeled Bug #1 on November 24, December 11 and December 24, 2024."
      }
    },
    {
      "schema_version": "1.2.0",
      "id": "meta-conversions-gateway-generated-script-boundary-2025",
      "title": "Meta Conversions API Gateway mixed configuration data with executable output",
      "organization": "Meta",
      "product": "Conversions API Gateway",
      "researchers": [
        "Youssef Sammouda"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "injection",
      "secondary_category_ids": [
        "client-security",
        "supply-chain"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "secure-parser-review",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "summary": "The researcher attributes a USD 250,000 award to the article’s separately identified backend finding, Bug #2.",
      "root_cause": "Configuration values were concatenated into generated JavaScript without context-safe serialization. Stored data thereby acquired the authority of executable output.",
      "impact": "The researcher reports stored script execution in consuming pages and potential account compromise. The article does not fully establish configuration-write prerequisites or independently substantiate its broader deployment and employee-system impact claims.",
      "defensive_takeaways": [
        "Keep configuration data separate from executable source; use context-appropriate serialization and structured interfaces.",
        "Treat shared analytics code as part of the consuming application’s trusted computing base.",
        "Document configuration-write permissions, downstream consumers and remediation coverage independently; do not infer universal compromise from shared distribution."
      ],
      "reward": {
        "amount": 250000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Meta",
        "evidence_level": "researcher_reported",
        "source_id": "researcher-writeup",
        "evidence_quote": "$250,000 bounty awarded by Meta for Bug #2",
        "evidence_location": "Timeline, January 16, 2025 entry explicitly assigned to Bug #2",
        "usd_equivalent": null,
        "notes": "Only Bug #2 is represented; Bug #1 has a distinct award and report identity. No awards are summed. The source uses $. USD is inferred from official 2020 program reporting, five years before this award, rather than an individual payment receipt. No bonus or settlement is established."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Current page header is January 13, 2026; a separately indexed 2025 URL also exists. Original publication versus archive migration or republication is not established."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Earliest public disclosure is not established."
        },
        "reported": {
          "value": "2024-11-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Timeline entry specifically identified as Bug #2."
        },
        "awarded": {
          "value": "2025-01-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Timeline entry specifically identified as Bug #2."
        },
        "fixed": {
          "value": "2025-01-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Timeline entry specifically identified as Bug #2."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": null,
        "basis": "published",
        "note": "Original publication is unknown. The January 2026 archive header is not counted as a new disclosure."
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://ysamm.com/uncategorized/2026/01/13/capig-xss.html",
          "title": "Multiple XSS in Meta Conversion API Gateway Leading to Zero-Click Account Takeover",
          "type": "researcher",
          "author": "Youssef Sammouda",
          "retrieved_at": "2026-10-03T09:50:24Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "report_identity"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Facebook Bug Bounty and BountyCon US-dollar reporting",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-03T09:50:24Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T09:50:24Z",
        "method": "Read the primary article and separately assigned reward timeline; reviewed official currency context and checked the existing report inventory for duplicate identity.",
        "limitations": [
          "Researcher-reported award; neither vendor confirmation of this individual award nor payment settlement was established.",
          "USD denomination uses official program context published five years before the award and is not an individual payment audit.",
          "Original publication remains unknown; current archive dates must not inflate recency.",
          "Only the backend configuration-to-script finding, labeled Bug #2, is included. The article also describes a different client-side finding with a separate award.",
          "Configuration-write prerequisites, remediation implementation and broad deployment or employee-system consequences are not independently verified.",
          "The narrative places investigation of Bug #2 after reporting Bug #1, while the labeled timeline dates Bug #2 first. Recorded event dates follow the explicit labels; no corrected chronology is inferred."
        ]
      },
      "content_scope": "historical_defensive_summary",
      "report_identity": {
        "kind": "source_label",
        "value": "Bug #2",
        "source_id": "researcher-writeup",
        "evidence_location": "Second bug heading; Timeline entries labeled Bug #2 on November 22, 2024, January 3 and January 16, 2025."
      }
    },
    {
      "schema_version": "1.1.0",
      "id": "meta-ai-media-object-authorization-2025",
      "title": "Meta AI media access lacked object-ownership authorization",
      "organization": "Meta",
      "product": "Meta AI media editing",
      "researchers": [
        "Sandeep (AppSecure)"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authorization",
      "secondary_category_ids": [
        "ai-security"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "defensive-evidence-writing",
        "patch-verification"
      ],
      "summary": "An authenticated media-editing operation exposed another user’s prompts and generated content because object ownership was not enforced. The researcher reports a USD 10,000 award.",
      "root_cause": "Authentication established a caller but did not bind the requested media object to that caller. The researcher’s two-user comparison exposed this distinction between feature access and content authority.",
      "impact": "The demonstration disclosed another user’s original prompt and generated media. Broader data harvesting was potential impact; the reproduced vendor response reports no evidence of abuse.",
      "defensive_takeaways": [
        "Editorial lesson: preserve ownership checks across derived-media and editing operations.",
        "Editorial lesson: distinguish temporary mitigation, full-fix confirmation and actual deployment timing."
      ],
      "reward": {
        "amount": 10000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Meta",
        "evidence_level": "researcher_reported_with_vendor_quote",
        "source_id": "researcher-writeup",
        "evidence_quote": "Total Bounty Awarded: 10000 USD",
        "evidence_location": "Timeline, corroborated by the reproduced vendor response in Fix & Meta’s Response.",
        "usd_equivalent": null,
        "notes": "The researcher explicitly states USD and reproduces the vendor award decision. Settlement is unverified."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Page is labeled Updated July 16, 2025; original publication is unknown."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "First public disclosure is not established; article update date is July 16, 2025."
        },
        "reported": {
          "value": "2024-12-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Full fix confirmed April 24, 2025; deployment date is not separately established."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": "2025-01-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Timeline labels this a temporary fix."
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": null,
        "basis": "published",
        "note": "Historical source updated July 16, 2025; original publication remains unknown and is not counted as recent."
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://www.appsecure.security/blog/meta-ai-prompt-and-genertaed-content-leakage-technical-analysis",
          "title": "Meta AI prompts and generated content: technical analysis",
          "type": "researcher",
          "author": "Sandeep / AppSecure",
          "retrieved_at": "2026-10-03T05:09:57Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T05:09:57Z",
        "method": "Fresh read of the primary researcher article through web text extraction; compared prerequisites, authorization boundary, demonstrated impact and remediation chronology with the existing record. No target testing or exploit reproduction.",
        "limitations": [
          "Vendor wording is researcher-published, not independent vendor confirmation.",
          "An updated date does not establish original publication. Full-fix confirmation does not establish deployment timing.",
          "Cash receipt is not established.",
          "The article attributes remediation to ownership checks but does not supply an independently reviewed patch."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "meta-accounts-center-linking-credential-confinement-2024",
      "title": "Meta Accounts Center linking lost credential and identity confinement",
      "organization": "Meta",
      "product": "Accounts Center Facebook–Instagram account linking",
      "researchers": [
        "Youssef Sammouda"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "authorization",
        "client-security"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "integration-threat-modeling",
        "security-token-design",
        "browser-isolation-review"
      ],
      "summary": "A researcher-reported USD 30,000 award documents a cross-product account-linking trust failure.",
      "root_cause": "SSO destination validation and browser-message confidentiality did not preserve account-linking credential confinement. Session identity could also differ from the person authorizing the connection, allowing linking authority to cross account boundaries.",
      "impact": "The researcher reports unauthorized Facebook linking and persistent account control. Prerequisites included an attacker-controlled Instagram account, account-specific authorization material, an authenticated Facebook user visiting attacker-controlled content, and user confirmation. Mobile sign-in is described as potential; no widespread exploitation is established.",
      "defensive_takeaways": [
        "Bind linking approval to both intended account identities, the initiating session, and the exact operation.",
        "Constrain credential delivery end to end, including browser-message recipients and final redirect destinations.",
        "Make identity changes visible and require fresh authorization when a sensitive linking flow changes account context.",
        "Treat these as defensive design recommendations rather than a reconstruction of the undisclosed vendor patch."
      ],
      "reward": {
        "amount": 30000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "evidence_level": "researcher_reported",
        "source_id": "researcher-writeup",
        "evidence_quote": "$30,000 bounty awarded by Meta",
        "evidence_location": "Timeline, November 27, 2024 entry",
        "usd_equivalent": null,
        "notes": "The article assigns one award to the reported finding. It uses $; USD is inferred from official February 2020 program-wide reporting, roughly five years before this award. That contextual source does not verify the individual denomination or settlement. No conflicting currency was identified.",
        "type": "bug_bounty",
        "awarding_organization": "Meta"
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Current article and archive index display January 15, 2026; original publication versus migration/republication is unverified. This header is not used to assert recent research."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Earliest public disclosure was not established."
        },
        "reported": {
          "value": "2024-10-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": "2024-11-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "fixed": {
          "value": "2024-11-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Overall researcher timeline label; component-level remediation and patch details are not independently verified."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": null,
        "basis": "published",
        "note": "Original publication remains unknown; the 2026 archive header does not establish recency."
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://ysamm.com/uncategorized/2026/01/15/steal-fxauth-leads-instagram-ato.html",
          "title": "Two-click Facebook account takeover via FXAuth token and blob theft",
          "type": "researcher",
          "author": "Youssef Sammouda",
          "retrieved_at": "2026-10-03T10:10:05.389636Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Una mirada retrospectiva a los aspectos más destacados de Bug Bounty 2019",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-03T10:10:05.389636Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-03T10:10:05.389636Z",
        "method": "Read the primary article and dated individual award, checked the researcher archive and official denomination context, and compared report identities with existing Meta records. Retained only conceptual defensive content.",
        "limitations": [
          "The award and overall fix are researcher-reported; vendor confirmation and cash settlement are unverified.",
          "Original publication is unknown, so no preferred-window inclusion is claimed.",
          "USD relies on earlier program-wide context rather than report-specific currency evidence.",
          "The source inconsistently names the final return host; no exact route or operational sequence is inferred.",
          "This account-linking report is counted once, not as separate records for its constituent weaknesses."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "facebook-sdk-message-authentication-randomness-2023",
      "title": "Facebook SDK message authentication relied on insecure randomness",
      "organization": "Meta",
      "product": "Facebook JavaScript SDK and mobile application web content",
      "researchers": [
        "Youssef Sammouda"
      ],
      "cve_ids": [],
      "cwe_mappings": [],
      "category_id": "authentication",
      "secondary_category_ids": [
        "client-security",
        "injection"
      ],
      "skillset_ids": [
        "security-token-design",
        "browser-isolation-review",
        "untrusted-input-handling",
        "integration-threat-modeling"
      ],
      "summary": "A USD 66,000 researcher-reported award illustrates how weak message authentication and unsafe rendering can invalidate an SDK trust boundary.",
      "root_cause": "The researcher followed messages from an embedded plugin into SDK handlers and examined their authority checks. A callback identifier was treated as an authentication secret despite coming from non-cryptographic randomness. Separately, a handler interpreted supplied content as active HTML. An origin check alone did not establish that the message content was authorized or safe to render.",
      "impact": "The researcher reports script execution and Facebook account takeover under mobile in-app browser conditions. Impact on an arbitrary embedding site depended on its framing controls. The article does not establish that every website using the SDK was affected equally.",
      "defensive_takeaways": [
        "Use cryptographic randomness and context binding for values that authorize message handling.",
        "Validate the sender, expected message relationship and permitted operation independently of rendering safety.",
        "Keep externally supplied content inert and review embedded-browser permissions as a separate trust boundary.",
        "Treat these as defensive design recommendations; the source dates a fix but does not establish the precise vendor patch implementation."
      ],
      "reward": {
        "amount": 66000,
        "currency": "USD",
        "scope": "single_report",
        "status": "awarded",
        "type": "bug_bounty",
        "awarding_organization": "Meta",
        "evidence_level": "researcher_reported",
        "source_id": "researcher-writeup",
        "evidence_quote": "$66,000 bounty awarded by Meta",
        "evidence_location": "Researcher timeline, dated award entry",
        "usd_equivalent": null,
        "notes": "One researcher-reported bug bounty, not an event total. The article uses $; prior official Meta program reporting supplies USD context. Actual cash settlement is not established."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Current archive page displays 2026-01-17. Original publication versus migration/republication is not established, so this date is not used as a recent disclosure."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Earliest public disclosure remains unverified; the current archive header does not resolve it."
        },
        "reported": {
          "value": "2023-06-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "awarded": {
          "value": "2023-06-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": null
        },
        "fixed": {
          "value": "2023-12-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher-writeup",
          "note": "Researcher timeline explicitly labels this as the vendor fix date."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": null,
        "basis": "published",
        "note": "Original publication is unknown; the January 2026 archive header is not counted as recent research. Report and award timelines remain separately dated."
      },
      "sources": [
        {
          "id": "researcher-writeup",
          "url": "https://ysamm.com/uncategorized/2026/01/17/math-random-facebook-sdk.html",
          "title": "Account Takeover in Facebook mobile app due to usage of cryptographically unsecure random number generator and XSS in Facebook JS SDK",
          "type": "researcher",
          "author": "Youssef Sammouda",
          "retrieved_at": "2026-10-02T19:21:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
          "title": "Facebook Bug Bounty and BountyCon US-dollar reporting",
          "type": "vendor",
          "author": "Dan Gurfinkel / Facebook",
          "retrieved_at": "2026-10-02T18:24:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "researcher-writeup",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T19:21:00Z",
        "method": "Re-read the SDK introduction, trust checks, randomness analysis, bounded impact and timeline. Expanded conceptual reasoning without adding reproduction instructions. Original publication remains unknown.",
        "limitations": [
          "Researcher-reported award; no independent vendor confirmation or audited transfer.",
          "January 2026 page dates may reflect publication or archive migration; original disclosure is not established.",
          "USD normalization uses earlier official program context rather than an award receipt."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "apple-smbfs-parser-state-consistency-2026",
      "title": "macOS SMBFS error handling left inconsistent kernel parser state",
      "organization": "Apple",
      "product": "macOS SMB filesystem",
      "researchers": [
        "Peter Malone"
      ],
      "cve_ids": [
        "CVE-2026-84543"
      ],
      "cwe_mappings": [],
      "category_id": "memory-safety",
      "secondary_category_ids": [
        "client-security"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "memory-safety-review",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "summary": "A rejected network response left inconsistent filesystem state. The researcher reports a $20,000 award and subsequent payment.",
      "root_cause": "The parser published a count before validating the associated allocation. Error cleanup did not restore the count and pointer together. The researcher compared parsing, cleanup and later consumption to explain why a failed validation still contaminated trusted kernel state.",
      "impact": "A Mac had to connect to a malicious SMB share; guest access was sufficient. The researcher demonstrated kernel panics on Apple silicon. Apple describes possible system termination or kernel-memory corruption. General-purpose code execution was not demonstrated.",
      "defensive_takeaways": [
        "Publish related parser fields atomically only after validation succeeds; reset them consistently on every failure.",
        "Require consumers to validate compound state, not merely individual fields.",
        "Apple reports improved bounds checking; the researcher's temporary-state design is a recommendation, not a verified patch description."
      ],
      "reward": {
        "amount": 20000,
        "currency": "USD",
        "scope": "single_vulnerability",
        "status": "paid",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "Apple notified me of the $20,000 bounty",
        "evidence_location": "Disclosure Timeline and following paragraph.",
        "usd_equivalent": null,
        "notes": "One CVE-specific award, not the researcher's cumulative earnings. Source uses $; Apple's official bounty announcement supplies US-dollar program context only.",
        "type": "bug_bounty",
        "awarding_organization": "Apple"
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original detailed README publication date was not established; advisory release is not substituted."
        },
        "public_disclosure": {
          "value": "2026-09-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor",
          "note": "Vendor security advisory; the researcher README publication date is not established."
        },
        "reported": {
          "value": "2026-05-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": "2026-05-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "fixed": {
          "value": "2026-09-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "vendor",
          "note": "Golden Gate 27 release and matching SMB advisory."
        },
        "paid": {
          "value": "2026-06-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": null,
        "basis": "published",
        "note": "Detailed publication date unknown; vendor advisory is dated September 14, 2026."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://github.com/petermalone/CVE-2026-84543",
          "title": "CVE-2026-84543: a remote kernel vulnerability in macOS SMBFS",
          "type": "researcher",
          "author": "Peter Malone",
          "retrieved_at": "2026-10-02T23:01:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "vendor",
          "url": "https://support.apple.com/en-us/149035",
          "title": "About the security content of macOS Golden Gate 27",
          "type": "vendor",
          "author": "Apple",
          "retrieved_at": "2026-10-02T23:01:00Z",
          "supports": [
            "dates",
            "impact",
            "remediation",
            "cve"
          ]
        },
        {
          "id": "currency-context",
          "url": "https://www.apple.com/nz/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/",
          "title": "Apple expands industry-leading commitment to protect users from highly targeted mercenary spyware",
          "type": "vendor",
          "author": "Apple",
          "retrieved_at": "2026-10-02T23:01:00Z",
          "supports": [
            "reward"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T23:06:13Z",
        "method": "Read primary public disclosures and corroborating sources; checked individual award scope. No target interaction or exploit reproduction.",
        "limitations": [
          "Payment is researcher-reported, not independently audited.",
          "Detailed disclosure publication date remains unknown.",
          "Researcher did not independently verify the production patch.",
          "USD denomination is inferred from Apple’s 2022 program announcement; the researcher states only $, and no contemporaneous currency-specific payment evidence was reviewed."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "apple-safari-media-permission-origin-confusion-2020",
      "title": "Safari origin confusion undermined stored media permissions",
      "organization": "Apple",
      "product": "Safari media permissions",
      "researchers": [
        "Ryan Pickren"
      ],
      "cve_ids": [
        "CVE-2020-3852",
        "CVE-2020-3864",
        "CVE-2020-3865"
      ],
      "cwe_mappings": [],
      "category_id": "client-security",
      "secondary_category_ids": [],
      "skillset_ids": [
        "browser-isolation-review",
        "secure-parser-review",
        "identity-lifecycle-review",
        "patch-verification"
      ],
      "summary": "The cited researcher documents a USD 75,000 award for this reported chain.",
      "root_cause": "URL parsing, origin identity, and secure-context decisions were inconsistent with the identity used for stored permissions. Defensive design should use one coherent origin model across permission enforcement.",
      "impact": "Unauthorized camera and microphone access under previously granted website permissions.",
      "defensive_takeaways": [
        "Use one coherent origin model for permission enforcement.",
        "Invalidate persistent consent when the underlying resource or trust context materially changes."
      ],
      "reward": {
        "amount": 75000,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "Apple",
        "status": "awarded",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "awarded me $75,000",
        "evidence_location": "Primary article award statement",
        "usd_equivalent": null,
        "notes": "One award for the reported vulnerability chain, not this amount per CVE."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The primary researcher page does not supply a publication date; no exact date is inferred."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": "2020-01-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "source-2",
          "note": "Safari 13.0.5 vendor release date; the advisory entry was added February 6."
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": null,
        "basis": "published",
        "note": "Historical chain with an undated primary write-up; exact publication recency is not asserted."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.ryanpickren.com/webcam-hacking-overview",
          "title": "Safari origin confusion undermined stored media permissions",
          "type": "researcher",
          "author": "Ryan Pickren",
          "retrieved_at": "2026-10-02T14:43:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "source-2",
          "url": "https://support.apple.com/en-sa/103780",
          "title": "Apple security release advisory",
          "type": "vendor",
          "author": "Apple",
          "retrieved_at": "2026-10-02T14:43:00Z",
          "supports": [
            "dates",
            "cve",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T14:43:00Z",
        "method": "Primary public sources read; individual reward, dates, and attribution reviewed. No target testing performed.",
        "limitations": [
          "One reported chain, not a $75,000 award for each CVE",
          "Broader project found seven bugs; source attributes this award to the camera exploit",
          "The researcher's page has no explicit publication date",
          "Publication date is unknown in the primary source, so recency is explicitly uncertain."
        ]
      },
      "content_scope": "historical_defensive_summary"
    },
    {
      "schema_version": "1.0.0",
      "id": "apple-icloud-sharing-consent-safari-origin-boundary-2022",
      "title": "iCloud sharing consent and Safari trust boundaries failed together",
      "organization": "Apple",
      "product": "iCloud Sharing and Safari",
      "researchers": [
        "Ryan Pickren"
      ],
      "cve_ids": [
        "CVE-2021-30861",
        "CVE-2021-30975"
      ],
      "cwe_mappings": [],
      "category_id": "client-security",
      "secondary_category_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "approval-state-integrity",
        "integration-threat-modeling",
        "identity-lifecycle-review"
      ],
      "summary": "The cited researcher documents a USD 100,500 award for this reported chain.",
      "root_cause": "Consent to open shared content remained effective after material content changes, and cross-application trust handling failed to preserve browser isolation. Review whether persisted consent remains valid as shared resources evolve.",
      "impact": "The researcher reports access across website security contexts and media permissions; additional research covered local-file exposure.",
      "defensive_takeaways": [
        "Use one coherent origin model for permission enforcement.",
        "Invalidate persistent consent when the underlying resource or trust context materially changes."
      ],
      "reward": {
        "amount": 100500,
        "currency": "USD",
        "scope": "single_report",
        "type": "bug_bounty",
        "awarding_organization": "Apple",
        "status": "awarded",
        "evidence_level": "researcher_reported",
        "source_id": "primary",
        "evidence_quote": "I reported this chain to Apple and was awarded $100,500 as a bounty.",
        "evidence_location": "Primary article award statement",
        "usd_equivalent": null,
        "notes": "One award for the reported vulnerability chain, not this amount per CVE."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The primary researcher page does not supply a publication date; no exact date is inferred."
        },
        "public_disclosure": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "reported": {
          "value": "2021-07",
          "precision": "month",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "awarded": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "fixed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "paid": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "award_announced": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "mitigated": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "recency": {
        "as_of": "2026-10-03",
        "window_start": "2025-10-03",
        "within_preferred_window": null,
        "basis": "published",
        "note": "Historical chain with an undated primary write-up; exact publication recency is not asserted."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.ryanpickren.com/safari-uxss",
          "title": "iCloud sharing consent and Safari trust boundaries failed together",
          "type": "researcher",
          "author": "Ryan Pickren",
          "retrieved_at": "2026-10-02T14:43:00Z",
          "supports": [
            "reward",
            "dates",
            "root_cause",
            "impact"
          ]
        },
        {
          "id": "source-2",
          "url": "https://support.apple.com/en-us/103237",
          "title": "Apple security release advisory",
          "type": "vendor",
          "author": "Apple",
          "retrieved_at": "2026-10-02T14:43:00Z",
          "supports": [
            "dates",
            "cve",
            "remediation"
          ]
        },
        {
          "id": "source-3",
          "url": "https://support.apple.com/en-us/103236",
          "title": "Apple security release advisory",
          "type": "vendor",
          "author": "Apple",
          "retrieved_at": "2026-10-02T14:43:00Z",
          "supports": [
            "dates",
            "cve",
            "remediation"
          ]
        }
      ],
      "primary_source_id": "primary",
      "verification": {
        "status": "included",
        "reviewed_at": "2026-10-02T14:43:00Z",
        "method": "Primary public sources read; individual reward, dates, and attribution reviewed. No target testing performed.",
        "limitations": [
          "One award for a reported chain; not a separate award per CVE",
          "Broader research included four bugs, only two used for the camera demonstration",
          "Complete remediation and payment dates are not stated; page says all issues patched by early 2022",
          "Publication date is unknown in the primary source, so recency is explicitly uncertain."
        ]
      },
      "content_scope": "historical_defensive_summary"
    }
  ]
}
