AI Data Use and Exposure Risks Across Bug Bounties, Consumer Apps, and LLM Training
HackerOne publicly addressed security researcher concerns that bug bounty submissions might be used to train its AI capabilities following the launch of its Agentic PTaaS offering. CEO Kara Sprague stated the company does not train generative AI models on researcher submissions or confidential customer data (internally or via third parties), describing its AI system (Hai) as intended to speed up outcomes like report validation and rewards rather than replace researchers; other bug bounty platforms (including Intigriti and Bugcrowd) similarly reiterated policies against using researcher data for AI model training.
Separately, a consumer Android app, “Video AI Art Generator & Maker,” exposed user content after researchers found an unsecured Google Cloud storage bucket containing 8.27 million media files, including roughly 2 million private user photos and videos, along with AI-generated media; the developer (Codeway) reportedly secured the bucket after disclosure, and another Codeway app had previously been linked to a large-scale exposure due to backend misconfiguration. In parallel, reporting on academic research and litigation highlighted that LLMs can be induced to reproduce near-verbatim copyrighted text from training data, with courts scrutinizing both the legality of training on copyrighted works and the separate issue of storing pirated datasets; AI vendors argued that extraction techniques are impractical for typical users and that models learn patterns rather than retain exact copies, while researchers and legal experts warned that verbatim reproduction can constitute copyright infringement and raises broader governance and data-handling risk for AI deployments.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
HackerOne addresses concerns over AI training on submissions
Following researcher concerns after the launch of its Agentic PTaaS offering, HackerOne CEO Kara Sprague said the company does not use bug bounty submissions or confidential customer data to train generative AI models, internally or through third parties.
Codeway secures exposed AI art app database
After the issue was identified, the developers reportedly secured the exposed database associated with the app.
Researchers discover exposed bucket for AI art app media
Security researchers found an unsecured Google Cloud Storage bucket tied to “Video AI Art Generator & Maker” that exposed 8.27 million media files, including about 2 million private user photos and videos, along with AI-generated content.
Video AI Art Generator app launched on Android
The Android app “Video AI Art Generator & Maker,” developed by Codeway Dijital Hizmetler Anonim Sirketi, was launched in mid-June 2023.
Codeway's Chat & Ask AI exposure is previously reported
Before the newly reported media leak, the same developer's separate app, “Chat & Ask AI,” had been linked to a misconfigured backend that exposed 300 million messages associated with 25 million users. The exact date is not provided in the reference.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


