







tldr: an attempt to reduce the terror reporting. There is no longer a curl bug-bounty program. It officially stops on January 31, 2026. After having had a few half-baked previous takes, in April 2019 we kicked off the first real curl bug-bounty with the help of Hackerone, and while it stumbled a bit at first … Continue reading The end of the curl bug-bounty →
What Happened to HackerOne?
The rise and fall of the largest bug bounty platform in the world

Mythos finds a curl vulnerability
yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

good-first-issue bot (@hacktober.tngl.sh)
Announcing good-first-issue tags added on @tangled.sh issues this October! Find them all at https://tangled.org/goodfirstissues source: https://tangled.org/@bad-example.com/hacktober-bot by @bad-example.com (not affiliated with tangled)
Django Joins curl in Pushing Back on AI Slop Security Report...
Django has updated its security policies to reject AI-generated vulnerability reports that include fabricated or unverifiable content.

Bug bounty businesses bombarded with AI slop
Never-ending" AI slop strains corporate hacking reward schemes.

Just a rumour of a bug is enough to find a security exploit these days
Thinking through how the conventional OSS security embargoes no longer buy us time, and what open source maintainers might do instead to respond



Updated: Data Breaches Caused by Leaks in 2024
We’re tracking data breaches that are most likely caused by leaked secrets and keeping this page up-to-date.

npm Worm Poisons keyv, cacheable and 400+ Other Packages Across Twelve Organisations
A worm moved one byte-identical credential stealer through more than 400 npm packages in twelve organisations on 4 August 2026, including @ornikar, @deliveroo, @servicetitan, @qlik, Picsart and the keyv and cacheable family. latest still resolves to a poisoned version on most affected names, and the payload installs a dead-man switch that fires when the stolen GitHub token is revoked, so rotating credentials first triggers it.

An update on the scraper situation
Our article 'Fighting the AI scraper bot scourge', published in early 2025, discussed the probl [...]
alright tanglers, it's back to shipping 🛳️ 🌐 Tangled Sites is here: serve websites straight from your repo. grab your `tngl.io` domain at tangled.org/settings/sites. already have a `tngl.sh` handle? that's your domain—ready to go! 📄 docs.tangled.org/hosting-websites-on-tangled.h…