We ❤️ 🐜🐞🦗🦟🦋. {echo,{{{Google,Chrome,Android,Abuse,Mobile,OSS,Cloud}Vulnerability,Patch}Reward,VulnerabilityResearchGrants}Program}

ESCAL8, Google’s annual flagship security conference, is coming to Singapore in October 2026, with a particular focus on AI Agents! 🇸🇬 Check out our blog post to see what's planned in the three main segments of the conference: bugSWAT, Hackceler8, and init.g() 👇 bughunters.google.com/blog/e…
10
88
6,829
📢📢📢 Attention bug hunters! Want to know more about how brutecat found a vulnerability in Google’s internal APIs, bypassing authorization to exploit the GFile library to gain access to internal filesystems and storage? If yes, check out his blog post 👇 bughunters.google.com/blog/b…
9
82
551
44,895
📢 Tracking our VRP rules just got easier! We are now mirroring our VRP rules and help articles directly on GitHub. Perfect for automating your workflows and tracking changes. 👇 github.com/google/bughunters
6
33
316
20,445
Teamwork makes the dream work 🙌 Google Bug Hunters now supports sharing the recognition (and splitting the financial reward) for reports you have submitted, but were researched and created in collaboration with other researchers. Details 👇 bughunters.google.com/about/…
5
9
110
10,107
Interested in crypto 🔒? Check out our latest post which analyzes recent results published by Anthropic and argues that these advances, while significant, do not signal the downfall of cryptography. bughunters.google.com/blog/m…
6
3
41
5,505
Check out Tomas' post and article on hacking Google using Git integrations. One of these reports even won him Most Valuable Hacker (MVH) at Google's bugSWAT event in Vegas last year!
The written version of my BSides Riga and @bsidesvilnius talks is up: exploiting git integrations in cloud services, with four bugs I found in GCP (Looker, Dataform), including the one that won me MVH. nopnop.pro/2026/06/17/exploi…
16
150
15,397
"brutecat is super talented", "luckily I'm not oncall ;)", "incredible" These are all real quotes from Googlers after seeing this blog post. Amazing work @brutecat, thank you for sharing!
Hacking Google with A.I. for $500,000 brutecat.com/r/hacking-googl…
1
27
572
38,512
📢 PSA for security researchers! In our latest post, we're taking a closer look at how Google Spark (which was recently launched) works, ways to approach bug hunting in Spark, and how to distinguish high-impact vulnerabilities from expected system behavior 👇 bughunters.google.com/blog/s…
3
9
109
10,506
📣Blast from the past📣 This post takes us back to a flaw discovered in 2010: while technology has advanced, the general story of how the flaw was detected is still a great example of effectively identifying and remediating a security issue. bughunters.google.com/blog/b…
2
4
35
3,867
📢 More on Google's approach to post-quantum cryptography 🔐 This time, we're taking a closer look at digital signatures and the complex challenges they present, and discussing the opinionated paths we are taking at Google in this space. bughunters.google.com/blog/n…
7
43
4,651
More on passkeys 🔐! This time we are focusing on storage options, in particular the differences between using a password manager vs. a hardware security key to store your credentials, and why you might choose one option over the other. bughunters.google.com/blog/h…
2
19
2,802
In April 2026, we held the latest edition of bugSWAT (our live event for security researchers) in Seoul, South Korea. For more information on this edition's focus, its impact & winners, as well as bugSWAT in general, see 👇 bughunters.google.com/blog/b…
2
13
79
7,976
📣📢 Calling all Android and Chrome bug hunters 🧑‍💻🔎! We're updating our Android & Chrome VRP programs to ensure we can continue to reward the most challenging and impactful vulnerabilities researchers find in our products. For details, 👇 bughunters.google.com/blog/e…
22
34
208
150,534
Our Google Cloud VRP researchers don't want to miss this! 🔥 Check out Omer's (@omer_asfu) cross-tenant bucket squatting research.
I achieved a cross-tenant #RCE in #GoogleCloud simply by abusing predictable bucket names. 🪣 In my latest research for @FocalSecurity, I look into "Bucket Squatting" - a cross-tenant attack that landed me 3 critical vulnerabilities in GCP. Here is how it works:
2
11
103
14,234
📢📢📢 Attention bug hunters! The Google VRP is updating its reward model, with a focus on the impact of vulnerabilities and the sensitivity of the data involved. To this end, we're introducing two dimensions: Information Tiers and Action Criticality. 👀👇 bughunters.google.com/blog/s…
9
37
241
21,176
Ever wondered how passkeys 🔐 work, and how they improve on classic passwords 🔤? For more details, see our latest post, and you'll also learn what makes passkeys particularly resistant against phishing 🐟. bughunters.google.com/blog/p…
1
4
39
11,473
📢 Open source security researchers, take note: we've updated the OSS VRP rules! We're emphasizing the need for actionable reports and verifiable reproduction steps – to allow us to focus on critical threats with real-world impact. For more details 👇 bughunters.google.com/blog/o…
1
13
78
8,407
GCP VRP Secrets? 🤫 Hear from the program leads! Michael Cote (linkedin.com/in/michaelpatri…) & Darby Hopkins (linkedin.com/in/darbyhopkins) join @ctbbpodcast to talk shop: killer report tips, program insights & boosting your bounty game on Google Cloud. 🎧 piped.video/7u6xpVhEpBA #GoogleVRP #BugBounty #CloudSecurity #GCP
1
6
57
9,420