Full-Time
Crowdsourced cybersecurity platform for vulnerability discovery
$172k - $236.5k/yr
Remote in USA
Remote
Remote within the United States.
Master's, PhD
See people who can refer or advise you
Bugcrowd runs a platform that connects businesses with a global community of security researchers to find and fix vulnerabilities in digital systems. It mainly runs bug bounty programs where companies offer rewards for researchers who report bugs, and it also provides services like attack surface management and remediation guidance. Researchers submit security findings through the platform, which coordinates the workflow, payments, and follow-up actions. The company differentiates itself by leveraging a large, global crowd of researchers and offering integrated services and compliance support (PCI DSS, GDPR, SOC 2, ISO 27001) in addition to bug bounties. Its goal is to help clients continuously improve their security posture and meet regulatory requirements by uncovering and addressing security risks before attackers can exploit them.
Company Size
1,001-5,000
Company Stage
Late Stage VC
Total Funding
$230.7M
Headquarters
San Francisco, California
Founded
2012
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Competitive salary & stock options
Opportunities to attend & host relevant conferences & meetup
Flexible vacation time
Medical, dental & vision coverage
Generous workstation allowance
Company-sponsored off-sites & celebrations
Pre-tax commuter benefits
401k
Apple caps bug reports after AI submissions blocked $200K macOS exploit. 2026-08-04 06:43:34 Key Takeaways * Apple implemented a vulnerability report cap in June to manage overwhelming AI-generated submissions of nonexistent flaws. * Bynario discovered 50+ macOS bugs including a $100,000-$200,000 privilege escalation exploit using ChatGPT. * Apple is now reviewing Bynario's work and allowing researchers to request higher submission quotas. Apple capped the number of vulnerability reports a researcher can file simultaneously after its security team was overwhelmed by AI-generated submissions that reported nonexistent flaws, the Financial Times reported. The cap, implemented in June with a 30-day cool-off period, prevented Milan-based cybersecurity startup Bynario from reporting a privilege escalation exploit chain valued between $100,000 and $200,000 on the criminal market. The restriction reflects a broader industry challenge as AI tools enable mass vulnerability discovery, with platforms like Bugcrowd reporting submission volumes quadrupling in March and competitors HackerOne and Nextcloud suspending their paid bug bounty programs in April. Bynario discovered 50+ macOS bugs using ChatGPT. Bynario used OpenAI's ChatGPT to surface more than 50 bugs in the latest version of macOS over three weeks, according to the Financial Times. Among the discoveries was a privilege escalation exploit chain, a class of flaw that hands an attacker unrestricted control of a machine. Chief executive Alfredo Pesoli stated the exploit's value on the criminal market ranged between $100,000 and $200,000. The firm could not report the vulnerability because Apple had already refused further submissions under the new cap. Apple told the Financial Times it is now in contact with Bynario and reviewing its work. Pesoli said "maintainers and vendors have been flooded by the sheer amount of bugs" being uncovered. Apple's security portal now requires researchers to apply for a bigger quota beyond the standard cap. Every alleged flaw still needs a human to confirm it, though Apple is using AI internally to triage the pile. Apple stated it had "recently adjusted the number of new reports a researcher can have open at once" and that researchers can ask for a higher limit at any time. Bug bounty platforms suspended programs amid submission surge. In May, security firm Bugcrowd said submissions through its platform more than quadrupled across three weeks in March, with most being fake. HackerOne and Nextcloud suspended their paid programs in April, with Nextcloud stating no rewards would be paid "regardless of severity" until it found a way to filter the low-effort reports. The volume is driven by rewards on offer, with Meta, Microsoft, Apple and Crypto.com paying out at least $58 million between them in 2025. Apple's own top tier reaches $5 million for a single finding. Vietnam-based security startup Calif carried an exploit to Apple's California headquarters in person in May, saying it wanted to avoid "getting buried in the submission flood" that entrants in hacking contest Pwn2Own had been caught in. Calif had used a preview version of AI tools to build the first public macOS kernel memory corruption exploit able to survive Memory Integrity Enforcement, the defence Apple announced last September. Calif found the bugs on April 25 and had a working exploit by May 1. Bynario tried the portal three months later and could not get in. Anthropic and OpenAI tools surfaced flaws in Apple updates. In security updates last week, Apple credited Anthropic and OpenAI software with surfacing flaws, and carried roughly five times the fixes of a normal cycle, according to the Financial Times. In March, Anthropic introduced Mythos, a cyber-focused model it initially restricted to selected technology companies, banks and researchers under Project Glasswing. Mozilla said the tool surfaced 271 vulnerabilities in Firefox during internal testing. Coinkite lost over $100 million to firmware exploit. Coldcard wallet manufacturer Coinkite suggested that AI was likely used to uncover a bug in its open source firmware that sat unnoticed for five years, enabling attackers to steal more than $100 million from its hardware wallets. Two months prior, Zcash disclosed that researcher Taylor Hornby, working with Claude Opus 4.8, had found two lines of code in its Orchard shielded pool that allowed undetectable counterfeiting of ZEC for four years. Zcash rolled out the Ironwood upgrade last month to address the vulnerability. Faq. What did Apple do to address the surge in AI-generated bug reports? Apple capped the number of vulnerability reports a researcher can file simultaneously and added a 30-day cool-off period on its security portal in June. Researchers must now apply for a bigger quota beyond the standard cap, and every alleged flaw still requires human confirmation, though Apple is using AI internally to triage submissions. Why did Bynario fail to report the macOS privilege escalation exploit? Bynario discovered more than 50 macOS bugs in three weeks using ChatGPT, including a privilege escalation exploit chain valued between $100,000 and $200,000. The firm could not report the vulnerability because Apple had already refused further submissions under the new cap implemented to manage the flood of AI-generated reports. How did AI tools contribute to Apple's recent security updates? In security updates last week, Apple credited Anthropic and OpenAI software with surfacing flaws and carried roughly five times the fixes of a normal cycle, according to the Financial Times. Anthropic's Mythos model, introduced in March and initially restricted to selected technology companies and researchers, surfaced 271 vulnerabilities in Firefox during Mozilla's internal testing. Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Bugcrowd launches Savant Pathseeker for continuous agentic pentesting. Crowdsourced cybersecurity company Bugcrowd Inc. today launched Savant Pathseeker, an agentic penetration testing tool that continuously tests external web applications and application programming interfaces for vulnerabilities and provides proof that the flaws it finds can actually be exploited. The product is the first in a new Agentic Offensive Testing line from the company and pairs automated testing at scale with on-demand access to Bugcrowd's community of human pentesters. Bugcrowd is pitching Savant Pathseeker as a fix for a coverage gap that forces security teams to choose between depth and breadth. High-value assets can sit exposed for months between manual pentests, the company argues. Scanners watch everything else but flag theoretical flaws without confirming which are real. The company frames it as a timing problem. Attackers have turned to AI to probe continuously, and a pentest run every few months cannot keep up. The tool runs purpose-built agents against external-facing applications and APIs continuously. Findings are validated automatically and surfaced in one platform, so teams are not stuck triaging raw scanner output. Each finding comes with reproducible proof of exploitability and audit-ready reporting intended for security teams, auditors and regulators. Built-in guardrails and a manual kill switch keep testing within a customer's defined scope. The tool integrates with Bugcrowd's existing services, including its penetration testing as a service, bug bounty and vulnerability disclosure programs, red team as a service and attack surface monitoring. Customers can escalate systems that warrant deeper investigation to human researchers within the same platform. Bugcrowd positions the automated testing as a complement to its researchers rather than a replacement. The agents handle continuous baseline coverage so human experts can concentrate on business logic flaws, exploit chains and zero-day vulnerabilities that automated tools tend to miss. "Every day, our research community uncovers the next generation of critical vulnerabilities, zero-days, business logic flaws, broken access controls, that automation and AI simply can't find," said Braden Russell, chief technology officer at Bugcrowd. "We built Savant Pathseeker with our customers, designed around that human edge, bringing agentic discovery, testing, and validation into one place so every layer of offensive security works seamlessly." The company said it does not use customer or researcher data to train or tune the models behind Savant Pathseeker. The product runs on frontier AI models with a proprietary layer of skills developed by Bugcrowd's in-house practitioners. Savant Pathseeker forms part of a broader effort Bugcrowd calls Savant, which aims to combine autonomous testing, human-led engagements and attack surface visibility into a single view of exploitable risk. Chris Steffen, vice president of research at Enterprise Management Associates Inc., said in the announcement that security teams are stuck between periodic manual pentests that leave assets exposed and high-volume scanners that generate noise without proving what is exploitable. As agentic pentesting tools enter the market, he said, the real differentiator will not be automation alone but how well vendors pair machine speed with human judgment. Savant Pathseeker is available today through an early access program, with general availability planned for later this year. Image: Bugcrowd. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from its Marketplace portal page and links. About SiliconANGLE Media SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
Bugcrowd has launched Savant Pathseeker, an agentic pentesting solution that continuously tests web applications and APIs across attack surfaces. The platform combines automated testing with on-demand access to Bugcrowd's global community of human security researchers for complex vulnerabilities requiring expert judgement. Savant Pathseeker delivers autonomous validation of findings with reproducible proof of exploitability and audit-ready reporting. It features built-in guardrails and a manual kill switch to ensure testing remains within defined scope. The solution integrates with Bugcrowd's existing services, including Penetration Testing as a Service, Bug Bounty, Vulnerability Disclosure Programme, and Red Team as a Service. Bugcrowd does not use customer or researcher data to train the AI models powering the platform. Savant Pathseeker is available through an early access programme, with general availability planned for later this year.
Searchlight Cyber appoints Paul Ciesielski as Chief Revenue Officer. Cybersecurity industry veteran joins Searchlight's executive team to scale global sales and drive the next phase of the company's expansion. PORTSMOUTH, UNITED KINGDOM, June 11, 2026 /EINPresswire.com/ - - Searchlight Cyber today announced the appointment of Paul Ciesielski as Chief Revenue Officer (CRO). The strategic hire marks a significant milestone in Searchlight's next phase of growth, as the company scales its operations to help enterprises, governments and law enforcement agencies preempt critical threats and stop cyber attacks. Ciesielski brings more than 20 years of experience in building and leading high-performance sales organizations within the cybersecurity and technology sectors. As CRO, he will be responsible for Searchlight's global go-to-market strategy, overseeing sales and channel partnerships to drive international revenue growth. The appointment follows the recent transition of Michael Gianarakis to CEO and serves as the next catalyst for Searchlight's continued expansion. Ciesielski's track record of scaling venture-backed and public companies will be instrumental as the company solidifies its position as the market leader in Preemptive Threat Exposure Management. Michael Gianarakis, CEO of Searchlight Cyber, commented: "We are thrilled to welcome Paul to the leadership team at such a pivotal moment for Searchlight. Paul is a proven leader with a deep understanding of the cybersecurity landscape, and is perfectly positioned to take innovative companies like Searchlight to the next level. His expertise will be invaluable as we continue to scale rapidly, ensuring that organizations worldwide can gain the critical edge over emerging threats." Paul Ciesielski, Chief Revenue Officer of Searchlight Cyber, said: "Searchlight has established a winning formula for preemptive cybersecurity, delivering a combination of market leading Attack Surface Management and Threat Intelligence to help organizations tackle increasingly sophisticated and accelerated exposure exploitation. I am excited to join this talented team and look forward to scaling our global operations to help more customers and partners gain the upper hand against their adversaries." Ciesielski joins Searchlight from Bugcrowd, a leader in crowdsourced cybersecurity, where he served as Chief Revenue Officer and played a core role in the company's expansion. His previous experience includes CRO roles at TRUEFORT, ReversingLabs and SevOne, as well as senior sales leadership positions at Chef Software, AppDynamics (acquired by Cisco), Mazu (acquired by Riverbed Technology), and Mercury (acquired by HP). About Searchlight: Searchlight Cyber was founded in 2017 with a mission to stop criminals from acting with impunity. With its pioneering Preemptive Threat Exposure Management (PTEM) offering, Searchlight helps organizations identify exposures and neutralize threats before attacks begin. Searchlight unifies leading Attack Surface Management, dark web intelligence, and risk management tools to help organizations separate the signal from the noise and prioritize the threats that matter. It is used by some of the world's largest enterprises, government and law enforcement agencies, and the managed security service providers at the forefront of protecting customers from external threats. Legal Disclaimer: EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
Bugcrowd expands platform with European Data Residency to support regional compliance needs. June 2, 2026 EU and EU-focused organizations can now leverage Bugcrowd's intelligent offensive security platform while ensuring all sensitive vulnerability data remains on European soil. SAN FRANCISCO - Bugcrowd, a leader in preemptive cybersecurity, today announced the launch of its Data Residency Option for the EU, a new configuration designed to meet the growing demand for regional data sovereignty. Bugcrowd is leveraging its enterprise-grade infrastructure to provide a dedicated EU-hosted environment in AWS Frankfurt. This strategic move allows European commercial entities to utilize global offensive security testing while ensuring sensitive personally identifiable information (PII) and vulnerability data never leaves the region. "Our new Data Residency option is built to fulfill the rapid cybersecurity risk reduction needs of customers while meeting the strict standard of EU data privacy regulations," said Braden Russell, Chief Technology Officer, Bugcrowd, "This configuration allows European customers and global organizations with an EU presence to benefit from the research, platform innovation, and support capabilities of a global cybersecurity leader while meeting regional requirements." The deployment helps customers meet EU data residency and data sovereignty expectations. Bugcrowd is now providing the infrastructure necessary for organizations to achieve data sovereignty without sacrificing innovation velocity or global scale. It targets high-security sectors including government, critical infrastructure, and financial services that have historically required localized data handling. Following its recent United States FedRAMP Moderate Authorization, this regional deployment provides the same high level of platform performance and researcher experience that Bugcrowd is known for. "According to a Gartner survey of IT leaders in Western Europe, 61% said geopolitical factors will increase their reliance on local or regional cloud providers, while 53% said geopolitics will restrict their organizations' future use of global cloud providers," said George Papakyriakopoulos CISO, Skroutz. "As a Bugcrowd customer, this new regional option directly addresses these concerns by providing the local storage we need while maintaining access to a global crowd of researchers. This initiative ensures that European companies like Skroutz can innovate securely and stay compliant within the region." The Data Residency Option for the EU is scheduled for full availability by July 1, marking a significant milestone in Bugcrowd's mission to protect the digitally connected world. As Bugcrowd continues to scale its global operations, it remains focused on delivering high-fidelity security results that bridge the gap between regional compliance and global resilience.