BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Eating Our Own Dogfood: Running a Bug Bounty Program
  on a Bug\n   Bounty Platform\n   Tags: Bug Bounty Village | Creator Talk/
 Panel\n   When: Saturday\, Aug 8\, 12:30 - 12:59 PDT\n   Where: LVCCW Leve
 l 1 Hall 3 1102 (Creator Stage 6) - [1]Map\n\n   Description:\n\n   At Hac
 kerOne\, the same community that submits vulnerability reports\n   also te
 sts the platform they use to report them. Every report becomes\n   a live 
 stress test of our product\, workflows\, assumptions\, and newly\n   shipp
 ed features. In this talk\, a Senior Triage Lead and a Product\n   Securit
 y Engineer share what we learned from running HackerOne’s own\n   bug bo
 unty program while shipping GraphQL features\, AI-assisted\n   tooling\, d
 isclosure workflows\, and platform-scale infrastructure\n   changes. Using
  three real disclosed reports\, we walk through how\n   seemingly small bu
 gs escalated into platform-wide security lessons: 1.\n   An Elasticsearch 
 query parameter that enabled metadata enumeration\n   through raw script e
 xecution. 2. A PDF export feature that\n   unintentionally exposed interna
 l triage activity. 3. An AI agent that\n   exposed non-public report metad
 ata because a researcher asked the\n   right question. We will show how re
 ports move from submission to\n   validation\, severity debates\, engineer
 ing response\, remediation\,\n   retesting\, and disclosure. We will also 
 discuss how we use our own\n   program as a testing ground for AI-assisted
  triage\, automated\n   validation workflows\, and disclosure policies bef
 ore rolling changes\n   out more broadly. This is not a “how to run a bu
 g bounty program”\n   talk. It is a behind-the-scenes look at what happe
 ns when hackers\n   continuously attack the bug bounty platform itself and
  how that\n   pressure forces rapid security evolution. Attendees will lea
 ve with\n   practical lessons on: 1. building tighter triage-to-engineerin
 g\n   feedback loops\, 2. handling modern attack surfaces like GraphQL and
  AI\n   agents\, 3. scaling remediation without losing researcher trust\, 
 4. and\n   turning bug bounty programs into product improvement engines in
 stead\n   of passive inboxes. All case studies are based on disclosed Hack
 erOne\n   reports. No customer data was accessed or exposed.\n\n   Speaker
 s:Shrimant Subhash More\,Martzen Haagsma\n\n   SpeakerBio:  Shrimant Subha
 sh More\, Senior Security Analyst\, HackerOne\n\n   Shrimant Subhash More 
 is a Senior Product Security Analyst at\n   HackerOne with over 8 years of
  experience in offensive security\,\n   penetration testing\, and vulnerab
 ility management. His expertise spans\n   web\, API\, mobile (Android and 
 iOS)\, and AI/LLM security\, with more\n   than 300 security assessments c
 onducted across diverse industry\n   sectors. At HackerOne\, Shrimant lead
 s and supports vulnerability\n   triage operations\, validates security re
 ports submitted by\n   researchers\, handles escalations\, mentors analyst
 s\, and collaborates\n   with global teams to improve security outcomes an
 d triage efficiency.\n   He is passionate about offensive security\, produ
 ct security\n   operations\, security automation\, and helping organizatio
 ns build\n   resilient products. Beyond his professional role\, Shrimant a
 ctively\n   contributes to the cybersecurity community as a HackerOne Comm
 unity\n   Brand Ambassador for India West (Pune)\, where he organizes meet
 ups\,\n   conducts workshops\, mentors aspiring researchers\, and promotes
 \n   responsible disclosure and bug bounty programs. He is the assignee of
 \n   CVE-2020-35296 and holds multiple industry certifications across\n   
 security\, cloud\, and AI domains.\n\n   SpeakerBio:  Martzen Haagsma\, Se
 curity Engineer\, HackerOne\n\n   Martzen Haagsma is a Product Security En
 gineer at HackerOne with a\n   passion for building secure systems through
  collaboration\, automation\,\n   and continuous learning. With experience
  spanning security testing\,\n   DevOps engineering\, and technical leader
 ship\, Martzen focuses on\n   helping organizations identify vulnerabiliti
 es\, improve security\n   processes\, and strengthen their overall securit
 y posture. Known for a\n   solution-oriented mindset and a strong belief i
 n the power of\n   teamwork\, Martzen enjoys connecting people\, sharing k
 nowledge\, and\n   turning complex security challenges into practical outc
 omes. Prior to\n   joining HackerOne\, Martzen worked across both public a
 nd private\n   sectors in roles involving security testing\, agile quality
 \n   engineering\, and engineering leadership. Outside of work\, Martzen i
 s\n   an active technologist with interests ranging from security and\n   
 software development to automation\, IoT\, and 3D printing. Through\n   wr
 iting\, mentoring\, and community engagement\, Martzen advocates for\n   c
 uriosity\, collaboration\, and making technology more secure and\n   acces
 sible for everyone.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T195900Z
DTSTART:20260808T193000Z
LOCATION:Bug Bounty Village - LVCCW Level 1 Hall 3 1102 (Creator Stage 6)
SUMMARY:Eating Our Own Dogfood: Running a Bug Bounty Program on a Bug Bount
 y Platform
END:VEVENT
END:VCALENDAR
