Skip to main content

Tag: vulnerability reward program

3 articles

Researchers work on computers at a brightly-lit tech workspace surrounded by whiteboards and notes.

Google Halts Open-Source Bug Bounty Payouts Amid Automated Report Surge

Google is hitting the pause button on its open-source bug bounty program due to a surge in automated submissions, most of which are invalid. The temporary suspension will be revisited in 2027 with a revamped program.

Analyst 207
A broken lock on a laptop screen amidst coding workspace symbolizes chatbot vulnerability.

Google Dialogflow Flaw Lets Rogue Agents Hijack Chatbots

A security flaw in Google Dialogflow, dubbed "Rogue Agent," allowed hackers to hijack chatbots, but thankfully, a fix was rolled out after Varonis reported the issue through Google's Vulnerability Reward Program. The flaw was cleverly exploited through custom Code Blocks in Dialogflow CX, highlighting the importance of robust security measures in chatbot development.

Analyst 207
Smartphone with notification on screen, surrounded by everyday objects.

Google Gemini on Android Exposed to Notification-Based Hijacking

Researchers have uncovered a vulnerability in Google Gemini on Android that allows hackers to hijack the assistant using a single hostile notification, no malicious app required. This shocking exploit lets anyone able to push a notification to a device deliver a payload and take control.

Analyst 207