ESCAL8, Google’s annual flagship security conference, is coming to Singapore in October 2026, with a particular focus on AI Agents! 🇸🇬
Check out our blog post to see what's planned in the three main segments of the conference: bugSWAT, Hackceler8, and init.g() 👇
bughunters.google.com/blog/e…
📢📢📢 Attention bug hunters!
Want to know more about how brutecat found a vulnerability in Google’s internal APIs, bypassing authorization to exploit the GFile library to gain access to internal filesystems and storage?
If yes, check out his blog post 👇
bughunters.google.com/blog/b…
📢 Tracking our VRP rules just got easier!
We are now mirroring our VRP rules and help articles directly on GitHub. Perfect for automating your workflows and tracking changes. 👇
github.com/google/bughunters
Teamwork makes the dream work 🙌
Google Bug Hunters now supports sharing the recognition (and splitting the financial reward) for reports you have submitted, but were researched and created in collaboration with other researchers. Details 👇
bughunters.google.com/about/…
Interested in crypto 🔒?
Check out our latest post which analyzes recent results published by Anthropic and argues that these advances, while significant, do not signal the downfall of cryptography.
bughunters.google.com/blog/m…
Check out Tomas' post and article on hacking Google using Git integrations. One of these reports even won him Most Valuable Hacker (MVH) at Google's bugSWAT event in Vegas last year!
The written version of my BSides Riga and @bsidesvilnius talks is up: exploiting git integrations in cloud services, with four bugs I found in GCP (Looker, Dataform), including the one that won me MVH.
nopnop.pro/2026/06/17/exploi…
"brutecat is super talented", "luckily I'm not oncall ;)", "incredible"
These are all real quotes from Googlers after seeing this blog post. Amazing work @brutecat, thank you for sharing!
📢 PSA for security researchers!
In our latest post, we're taking a closer look at how Google Spark (which was recently launched) works, ways to approach bug hunting in Spark, and how to distinguish high-impact vulnerabilities from expected system behavior 👇
bughunters.google.com/blog/s…
📣Blast from the past📣
This post takes us back to a flaw discovered in 2010: while technology has advanced, the general story of how the flaw was detected is still a great example of effectively identifying and remediating a security issue.
bughunters.google.com/blog/b…
📢 More on Google's approach to post-quantum cryptography 🔐
This time, we're taking a closer look at digital signatures and the complex challenges they present, and discussing the opinionated paths we are taking at Google in this space.
bughunters.google.com/blog/n…
More on passkeys 🔐!
This time we are focusing on storage options, in particular the differences between using a password manager vs. a hardware security key to store your credentials, and why you might choose one option over the other.
bughunters.google.com/blog/h…
In April 2026, we held the latest edition of bugSWAT (our live event for security researchers) in Seoul, South Korea.
For more information on this edition's focus, its impact & winners, as well as bugSWAT in general, see 👇
bughunters.google.com/blog/b…
📣📢 Calling all Android and Chrome bug hunters 🧑💻🔎!
We're updating our Android & Chrome VRP programs to ensure we can continue to reward the most challenging and impactful vulnerabilities researchers find in our products. For details, 👇
bughunters.google.com/blog/e…
I achieved a cross-tenant #RCE in #GoogleCloud simply by abusing predictable bucket names. 🪣
In my latest research for @FocalSecurity, I look into "Bucket Squatting" - a cross-tenant attack that landed me 3 critical vulnerabilities in GCP.
Here is how it works:
📢📢📢 Attention bug hunters!
The Google VRP is updating its reward model, with a focus on the impact of vulnerabilities and the sensitivity of the data involved. To this end, we're introducing two dimensions: Information Tiers and Action Criticality. 👀👇
bughunters.google.com/blog/s…
Ever wondered how passkeys 🔐 work, and how they improve on classic passwords 🔤?
For more details, see our latest post, and you'll also learn what makes passkeys particularly resistant against phishing 🐟.
bughunters.google.com/blog/p…
📢 Open source security researchers, take note: we've updated the OSS VRP rules! We're emphasizing the need for actionable reports and verifiable reproduction steps – to allow us to focus on critical threats with real-world impact.
For more details 👇
bughunters.google.com/blog/o…