Skip to main content

August 2026 Changelog

A full collection of changes released during the month of August

IDV Required Before BBP Submission (Phase 1: New Accounts Only)

From midnight tonight (August 5, 2026) UTC, all new accounts must be ID-verified before submitting to a bug bounty program. Existing accounts will be updated with this requirement on August 14. VDPs stay wide open throughout.

What we did:

  • Gated BBP submission on ID verification for new accounts, across web, report assistant, and the Hacker API.

  • Removed the old "one valid report" prerequisite before ID verification can be completed.

  • Added a clear in-product banner at the point of submission with a direct route to verify. Draft reports auto-save, so nobody loses their work.

  • Added a dedicated Hacker API error so blocked automations get a real reason and a verification link, instead of a generic 403.

Why we did it:

  • Report generation got cheap and fast. Low-signal volume followed.

  • New accounts are the sharpest end of the problem. Account creation costs nothing, so a throttled account gets replaced in minutes.

  • Identity is the anchor rate limits never had.

  • Phasing new accounts first lets us watch VRM load and verification spend before the full researcher pool reaches the gate on August 14.

Who it helps:

  • Bug bounty customers: the cheapest route to low-signal volume starts closing today.

  • Researchers: a new account verifies once and starts building a reputation against a real identity.

  • Triage and VRM: less throwaway-account volume to work through.

How to use it:

Nothing to configure. Applies automatically to every bug bounty program, public and private, managed and unmanaged. Researchers verify at Profile > ID verification + Clear.

What's next:

  • August 14: the requirement extends to existing accounts, with anyone holding a valid report in the last 12 months exempt at launch.

Remediation Dashboard

Summary:

A new Remediation dashboard is live in Analytics for all customers. The dashboard shows how valid vulnerabilities move from discovery to fix, how fast remediation happens, and what the unresolved backlog costs in USD. Works on its own for any customer, and complements H1 Remediation for accounts who have it.

What we did:

  • Shipped a new Remediation dashboard covering the flow from discovery to fix, MTTR trends against history and peers, backlog ageing, and the cost of open exposure risk.

  • Introduced a new metric, Carrying cost of exposure debt, which connects to. Return on Mitigation. RoM prices the risk that a customer has removed. Carrying costs of exposure debt price in the risk are still sitting in their backlog. Same Annual Loss Expectancy model, same org settings, opposite side of the ledger.

  • Added Findings flow, the first view tracing every finding through the full funnel in one chart, from all findings through valid, to a remediation plan created, to remediated, coloured by severity. It exposes the gap between a valid finding and a plan to fix it.

  • Added Days to zero backlog, our first forward-looking metric in Analytics. It turns 90 days of discovery and remediation rates into a timeline to clear the current backlog, with a separate figure for High and Critical.

  • Corrected MTTR to count valid reports only, and updated the Executive dashboard to match.

Why we did it:

Discovery is no longer the bottleneck, the market finds fast and. Remediation is. Submissions grew 76% year on year, while the unresolved critical backlog grew. Customers had no visibility into how their backlog ages, and no way to put a number on the risk left open. Return on Mitigation demonstrates the value of delivered fixes. Nothing priced the work at an outstanding level, which is the number a CISO needs when asking a board for remediation capacity, and also supports a use case for our new Remediation product.

Who it helps:

  • CISOs and security leaders who report risk to a board in dollars rather than vulnerability counts.

  • Program Managers who need evidence remediation keep pace with discovery, and a case for more capacity when the gap widens.

  • CSMs and AEs in QBRs and renewal conversations. Use this when an account questions the value of Triage spend or Remediation spend,, or asks how their MTTR compares with peers.

How to use it:

  • Open Analytics -> Remediation.

  • Read three surfaces together: Discovery to remediation trend for direction, Vulnerabilities by age for the standing backlog, and Days to zero backlog for the timeline.

  • Use Findings flow to find where valid findings stall before anyone plans a fix.

  • Use the Carrying cost charts to sequence remediation by money. A handful of critical findings outweigh a large volume of low-severity ones.

  • Org Admins set the inputs behind the dollar figures in Settings > Return On Mitigation. The same inputs drive Return on Mitigation, so both dashboards stay consistent.

Learn more: Docsite page

Did this answer your question?