← Intelligence
post 2026-05-13

First Bounty Awarded

FARPSEC receives its first paid vulnerability bounty through coordinated disclosure on HackerOne. Details after remediation.

Maliq Barnard Founder

<p>FARPSEC just got paid for its first vulnerability report.</p>
<p>The bug turned up during a deep audit of a macOS security product. I reported it through the vendor's bug bounty program on HackerOne, and it was triaged a couple of days later.</p>

<h2>What I can say so far</h2>
<ul>
<li><strong>Platform:</strong> HackerOne</li>
<li><strong>Severity:</strong> High</li>
<li><strong>Status:</strong> Triaged, fix in progress</li>
<li><strong>Bounty:</strong> Paid</li>
</ul>

<p>That's about all I can share right now. The full writeup, covering what the bug is, the root cause, and how the proof of concept works, goes up here once the vendor ships a fix and the report is opened to the public under HackerOne's coordinated disclosure policy.</p>

<h2>Why this one matters to me</h2>
<p>It's the first paid result out of the FARPSEC research pipeline, which is a good sign the approach holds up. There are more findings from the same audit already queued for submission, and I'll update this post as the disclosure process moves along.</p>

<p><em>This is a placeholder. It gets replaced with the full article once coordinated disclosure is done.</em></p>

<p><strong>Analyst:</strong> Maliq Barnard<br><strong>Date:</strong> 13 MAY 2026</p>