Turso has announced the discontinuation of its bug bounty program. The decision comes as the company shifts its security strategy.
Turso, a SQLite-compatible database platform, is ending its public bug bounty initiative. The company did not disclose specific reasons for the retirement in its announcement.
Bug bounty programs incentivize independent security researchers to identify and report vulnerabilities before they can be exploited. Organizations typically use them as a cost-effective complement to internal security testing.
The announcement sparked significant discussion in the developer community, with 223 comments on Hacker News reflecting mixed reactions. Some questioned the implications for security posture, while others noted potential shifts in how companies approach vulnerability disclosure.
Turso's decision aligns with broader industry trends where some organizations consolidate security programs or transition to alternative vulnerability management approaches. Companies may retire bounty programs due to resource allocation changes, shift to managed security services, or internal restructuring.
No details were provided regarding timelines for existing bounty submissions or changes to Turso's vulnerability disclosure policy.
Manchester Airports Group disclosed a breach affecting Manchester, Stansted, and East Midlands airports. Hackers accessed data from approximately 8.7 million customers.
A lawsuit alleges that Elon Musk's xAI trained its Grok language models using child sexual abuse material, including both real and AI-generated imagery.
The ShinyHunters extortion group has published sensitive data from nearly 13 million Carhartt customer accounts stolen earlier this month, according to data breach notification service Have I Been Pwned.
A Russian-speaking ransomware gang called Aur0ra exploited SpaceX's Cursor AI coding assistant to breach at least seven companies between mid-April and late May, according to security firm Gambit Security.