Bug bounty these days is like:
"We regret to inform you that BigStinkyCompany is pausing all submissions until further notice. We're excited to add "subdomain.stinky.com" to our assets after this break, but we're lowering our Medium and Low payouts in line with industry standards"
I’ve been strongly considering creating a YouTube channel for MonkeHacks in parallel with the newsletters. I don’t make money on it, so it’s just for fun. And I think it would be nice to have some more resources out there on hacking AI and navigating the bug bounty landscape rn.
Here's an example from nature that I find fits well. A tree that is 10% taller than its neighbor doesn't just get 10% more light; it secures a multiplier that allows it to grow exponentially faster. So thhe taller tree expands its leaves, captures a disproportionate share of light, and casts a shadow below. The slightly shorter tree receives a fraction of the multiplier (less light), stunts further, and eventually dies from light starvation.
One of the problems with bug bounty is that you can report the most severe bug that the company may ever see in its lifetime and it'll sit in platform triage queues for a few days before the team even sees it
I'm in Sweden now to unwind after Def Con. Nice 22 degree weather, no more stinky 45 degrees. 3 days of not thinking about hacking or AI and then back to tokenmaxxing 💀
“Security researchers are doomed because of AI.”
I kept hearing versions of this, so I went back through 500 years of people saying the same thing every time a machine learned a human skill.
Some were idiots.
Some were right.
Here’s where I landed.
NEW: Someone jammed the in-flight Wi-Fi on a Delta plane after the Def Con hacking conference in Las Vegas and replaced it with a malicious network.
Pilots alerted air traffic control: “We believe they are trying to scam the [other passengers].”
techcrunch.com/2026/08/11/de…