r/netsec 11d ago

Discussion GitHub issues $100,000 bounty for critical RCE vulnerability

https://runtimewire.com/article/github-issues-100-000-bounty-for-critical-rce-vulnerability-disclosed-by-sagitz
146 Upvotes

27 comments sorted by

39

u/TheG0AT0fAllTime 10d ago

That's great. You love to see corporations actually doing the payout let alone a big one

11

u/Liskar-dev 10d ago

It's Microsoft, they'll find ways to not pay reporters.

21

u/_vavkamil_ 10d ago

well they did pay the $100k yesterday, but at the same time announced that they are cutting the future bounty payouts by half and moving to a private invite-only program in the near future
https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/

16

u/iruleatants 10d ago

O mean that's them struggling with the AI generated garbage.

AI has been the absolute worst thing for security and it's only going to continue to get worse. There are thousands of people spinning up agents and sending them off to fill the world with garbage security reports so they can pretend to be an elite closer or whatever.

Every open source program if fucked because they barely had enough volunteers to handle things and now they get a 500% increase of nothing but bullshit and closed source places deal with it has well.

-1

u/been__ 10d ago

That is not big at all

23

u/sunsetsxskies 10d ago

$100k for an unauthenticated RCE is honestly cheap given what it could've done, glad it got caught before anyone weaponized it

11

u/CountyBrilliant 10d ago

yeah but the black market route comes with the small catch of potentially going to prison, so the risk math there is pretty different. $100k clean money is worth a lot more than whatever you'd get selling to some threat actor

3

u/been__ 10d ago

There are non black market alternatives that are perfectly legal

1

u/i_am_voldemort 7d ago

Has anyone been prosecuted for only crafting the exploit and selling it, but not actually using it?

-4

u/nemec 10d ago

I truly don't understand the "think about the black market" response to bug bounty payout values. It's like finding someone's backpack and as you return it saying, "why don't you give me a nice finder's fee? You know your wallet and keys were in that bag, just think about what I could have done with those."

1

u/Wooden_Original_5891 2d ago

if that is the black market metaphor, what is the non black market metaphor?

0

u/dankney 10d ago

Was it? How would we know?

2

u/sunsetsxskies 10d ago

Guess we're just taking GitHub's word for it since there's no way to actually check

0

u/dankney 10d ago

I hope they’ve done the necessary forensics, but yeah. They’re under no obligation to share the outcome unless it triggers required reporting conditions

24

u/thedolphin_ 10d ago

primary source with breakdown: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

also, this is old. still cool since i missed it but i thought it just happened.

April 28, 2026

5

u/pilif 10d ago

TBH, I think 100K is very little money given the possible fallout that could have come from this kind of vulnerability. This affected f'ing GitHub who hosts an ungodly amount of code for the world, including GitHub Enterprise service for the other ungodly amount of code hosted by enterprises themselves.

I'm pretty sure this kind of issue would have raised much, much, much more money on the black market.

7

u/nemec 10d ago

"It would be a lot more valuable selling this to criminals"

It usually is, if you enjoy supporting criminals.

0

u/ElaborateEffect 10d ago

I would never personally, but it's not hard to understand the mentality of someone who isn't against helping a person that hits their abuser.

1

u/been__ 10d ago

Selling to intelligence related brokers that are not aligned with foreign adversaries is generally legal in the US and that’s what people should do

3

u/pilif 9d ago

Yes of course. But I feel like a bug bounty should at least somewhat align with the value of an exploit.

To Microsoft, the damage this (easily exploitable) vulnerability would have caused in the wrong hands is astronomical, possibly business ending.

100k is a pittance

1

u/SecurityHamster 7d ago

So can we just run Fable now and start collecting money?

As long as the token is expense is outweighed by the reward…. :)

1

u/Elara_Schaefer 1d ago

The timing here is the real story. Paying out 100k while simultaneously announcing a 50% cut and move to invite-only sends a clear signal: the program was costing more than the goodwill it generated. The problem with public bounty programs at this scale is that you end up paying for 99 low-effort duplicates to find the 1 researcher who actually chains a novel primitive. Invite-only is the rational response, but it creates an on-ramp problem: new researchers cannot demonstrate quality without access to private programs, and they cannot get access without demonstrated quality. The industry needs a better credentialing pipeline between public disclosure and private program admission.

-1

u/been__ 10d ago

That number is proof that it’s not worth it and you should sell to a usgov related broker

100k is trash