Hacking, AppSec, and Bug Bounty newsletter

2017-06-21 | How to switch off a country, libdheap, and APIs with ZAP

Wednesday, June 21

Make it a great day and enjoy the summer solstice!



  • Subdomain takeover #3 at [30 upvotes] - $1,000 bounty for this report to HackerOne by @ak1t4. The info. subdomain takeovers showcase some of the complexities for companies using 3rd party services. Check out some good conversations in report #4 as well.

 You can see all the latest and greatest disclosures and bounties on  



Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.  

Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?

Have a news tip / story to highlight? We’d love to hear about it. Email: 

Get this email forwarded to you? Click here to subscribe to the Zero Daily

"I love Uber more than anything in the world and at this difficult moment in my personal life I have accepted the investor's request to step aside so that Uber can go back to building rather than be distracted with another fight..."

Travis Kalanick


HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty solutions encompass vulnerability assessment, crowdsourced security testing and responsible disclosure management. Discover more about our hacker powered security testing solutions or Contact Us today.