200 reports, 11 valid bugs, 0 critical issues. Why our HackerOne VDP was still worth it

DEV CommunityTuesday, November 18, 2025 at 2:15:14 PM
  • The Vulnerability Disclosure Program (VDP) launched on HackerOne in July 2024 received 200 reports over a year, resulting in 11 valid bugs but no critical vulnerabilities. This program transitioned from private to public, allowing better management of bug reports and improving the context provided to developers.
  • The initiative, despite the low yield of serious issues, is significant as it enhanced the overall security posture by addressing minor vulnerabilities and optimizing reporting processes, ultimately leading to more efficient development practices.
— via World Pulse Now AI Editorial System

Was this article worth reading? Share it

Recommended Readings
AI Amnesia: Erasing Knowledge Without a Trace
PositiveArtificial Intelligence
The article discusses a novel approach to address the issue of AI amnesia, where AI models may inadvertently retain sensitive information. Traditional methods for deleting such data often require complete retraining of the model, which is costly and time-consuming. The new technique involves creating artificial 'forgetting cues' that help the model unlearn specific data patterns by presenting it with synthetic examples that contradict the unwanted information, allowing for targeted knowledge removal without needing access to the original data.