Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposurecloud-misconfigurationai-platform-securityleaked-secret-api-key

AI Data Use and Exposure Risks Across Bug Bounties, Consumer Apps, and LLM Training

Updated 3mo agoFirst seen Feb 24, 20262 sources

HackerOne publicly addressed security researcher concerns that bug bounty submissions might be used to train its AI capabilities following the launch of its Agentic PTaaS offering. CEO Kara Sprague stated the company does not train generative AI models on researcher submissions or confidential customer data (internally or via third parties), describing its AI system (Hai) as intended to speed up outcomes like report validation and rewards rather than replace researchers; other bug bounty platforms (including Intigriti and Bugcrowd) similarly reiterated policies against using researcher data for AI model training.

Separately, a consumer Android app, “Video AI Art Generator & Maker,” exposed user content after researchers found an unsecured Google Cloud storage bucket containing 8.27 million media files, including roughly 2 million private user photos and videos, along with AI-generated media; the developer (Codeway) reportedly secured the bucket after disclosure, and another Codeway app had previously been linked to a large-scale exposure due to backend misconfiguration. In parallel, reporting on academic research and litigation highlighted that LLMs can be induced to reproduce near-verbatim copyrighted text from training data, with courts scrutinizing both the legality of training on copyrighted works and the separate issue of storing pirated datasets; AI vendors argued that extraction techniques are impractical for typical users and that models learn patterns rather than retain exact copies, while researchers and legal experts warned that verbatim reproduction can constitute copyright infringement and raises broader governance and data-handling risk for AI deployments.

Share:
AI Data Use and Exposure Risks Across Bug Bounties, Consumer Apps, and LLM Training
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 24, 20264mo ago

HackerOne addresses concerns over AI training on submissions

Following researcher concerns after the launch of its Agentic PTaaS offering, HackerOne CEO Kara Sprague said the company does not use bug bounty submissions or confidential customer data to train generative AI models, internally or through third parties.

Feb 23, 20264mo ago

Codeway secures exposed AI art app database

After the issue was identified, the developers reportedly secured the exposed database associated with the app.

Researchers discover exposed bucket for AI art app media

Security researchers found an unsecured Google Cloud Storage bucket tied to “Video AI Art Generator & Maker” that exposed 8.27 million media files, including about 2 million private user photos and videos, along with AI-generated content.

Jun 15, 20233y ago

Video AI Art Generator app launched on Android

The Android app “Video AI Art Generator & Maker,” developed by Codeway Dijital Hizmetler Anonim Sirketi, was launched in mid-June 2023.

Codeway's Chat & Ask AI exposure is previously reported

Before the newly reported media leak, the same developer's separate app, “Chat & Ask AI,” had been linked to a misconfigured backend that exposed 300 million messages associated with 25 million users. The exact date is not provided in the reference.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.