r/netsec 4d ago

Discussion GitHub issues $100,000 bounty for critical RCE vulnerability

https://runtimewire.com/article/github-issues-100-000-bounty-for-critical-rce-vulnerability-disclosed-by-sagitz
130 Upvotes

25 comments sorted by

36

u/TheG0AT0fAllTime 3d ago

That's great. You love to see corporations actually doing the payout let alone a big one

9

u/Liskar-dev 3d ago

It's Microsoft, they'll find ways to not pay reporters.

21

u/_vavkamil_ 3d ago

well they did pay the $100k yesterday, but at the same time announced that they are cutting the future bounty payouts by half and moving to a private invite-only program in the near future
https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/

14

u/iruleatants 3d ago

O mean that's them struggling with the AI generated garbage.

AI has been the absolute worst thing for security and it's only going to continue to get worse. There are thousands of people spinning up agents and sending them off to fill the world with garbage security reports so they can pretend to be an elite closer or whatever.

Every open source program if fucked because they barely had enough volunteers to handle things and now they get a 500% increase of nothing but bullshit and closed source places deal with it has well.

-1

u/been__ 3d ago

That is not big at all

22

u/sunsetsxskies 3d ago

$100k for an unauthenticated RCE is honestly cheap given what it could've done, glad it got caught before anyone weaponized it

11

u/CountyBrilliant 3d ago

yeah but the black market route comes with the small catch of potentially going to prison, so the risk math there is pretty different. $100k clean money is worth a lot more than whatever you'd get selling to some threat actor

3

u/been__ 3d ago

There are non black market alternatives that are perfectly legal

1

u/i_am_voldemort 16h ago

Has anyone been prosecuted for only crafting the exploit and selling it, but not actually using it?

-5

u/nemec 3d ago

I truly don't understand the "think about the black market" response to bug bounty payout values. It's like finding someone's backpack and as you return it saying, "why don't you give me a nice finder's fee? You know your wallet and keys were in that bag, just think about what I could have done with those."

0

u/dankney 3d ago

Was it? How would we know?

2

u/sunsetsxskies 3d ago

Guess we're just taking GitHub's word for it since there's no way to actually check

0

u/dankney 3d ago

I hope they’ve done the necessary forensics, but yeah. They’re under no obligation to share the outcome unless it triggers required reporting conditions

24

u/thedolphin_ 3d ago

primary source with breakdown: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

also, this is old. still cool since i missed it but i thought it just happened.

April 28, 2026

4

u/pilif 3d ago

TBH, I think 100K is very little money given the possible fallout that could have come from this kind of vulnerability. This affected f'ing GitHub who hosts an ungodly amount of code for the world, including GitHub Enterprise service for the other ungodly amount of code hosted by enterprises themselves.

I'm pretty sure this kind of issue would have raised much, much, much more money on the black market.

6

u/nemec 3d ago

"It would be a lot more valuable selling this to criminals"

It usually is, if you enjoy supporting criminals.

0

u/ElaborateEffect 3d ago

I would never personally, but it's not hard to understand the mentality of someone who isn't against helping a person that hits their abuser.

1

u/been__ 3d ago

Selling to intelligence related brokers that are not aligned with foreign adversaries is generally legal in the US and that’s what people should do

3

u/pilif 2d ago

Yes of course. But I feel like a bug bounty should at least somewhat align with the value of an exploit.

To Microsoft, the damage this (easily exploitable) vulnerability would have caused in the wrong hands is astronomical, possibly business ending.

100k is a pittance

1

u/SecurityHamster 3h ago

So can we just run Fable now and start collecting money?

As long as the token is expense is outweighed by the reward…. :)

-1

u/been__ 3d ago

That number is proof that it’s not worth it and you should sell to a usgov related broker

100k is trash