Severity Required for Bug Bounty, VDP, and Challenge Submissions
Starting September 21, 2026, severity becomes mandatory when submitting a report to Bug Bounty, Vulnerability Disclosure, and Challenge programs, both new and existing. Programs can opt out in program settings after that date if severity doesn't fit their workflow.
What we did:
Made severity required by default at submission across Bug Bounty, VDP, and Challenge programs. Programs choose which severity methods apply: CVSS 3.1, CVSS 3.0 HackerOne, CVSS 4.0, or manual selection.
Why we did it:
Triage now routes reports based on their initial severity. Reports without severity were missing priority routing, so genuinely critical reports sat in the backlog looking unprioritized. This closes that gap at submission.
Who it helps:
Triage: reports arrive pre-sorted, so routing is faster and more accurate.
Programs: critical and high reports are seen sooner, rather than waiting behind unclassified ones.
Researchers: a clear, consistent expectation that severity is part of a complete submission.
How to use it:
Nothing to configure to receive severity on new reports. To opt out after September 21, or to choose which severity methods your program accepts (CVSS 3.1, CVSS 3.0 HackerOne, CVSS 4.0, or manual), go to your program settings.
Create & Update Asset Tags via CSV Import and API
Asset tags, including custom categories, for example, Business Unit, can now be created and updated in bulk via CSV import, in the UI and via the API.
What we did:
The asset CSV export has always included an asset_tags column, but the importer ignored it. It now reads that column. Each cell is authoritative for the categories it names; unnamed categories are untouched, a blank cell changes nothing, and new categories and tags are created automatically.
Why we did it:
Bulk tagging was the top blocker for adopting tag-driven scope and reward groups. Customers had to tag assets one at a time in the UI or script it after every import.
Who it helps:
Organizations with large asset inventories, and anyone using asset tags to drive Unified Scope & Rewards groups.
How to use it:
Export from the Asset Inventory, edit the asset_tags column using Category::Tag (tab-separated), and re-import via Add Assets > Import from CSV. The downloadable example file includes the column for new assets, and the same file works via the API POST /v1/organizations/{id}/asset_imports. Keep files tab-separated. Requires the Asset inventory manager permission.
Documentation: Asset Filtering and Tagging · Asset Details and Scoping · Unified Scope & Rewards Setup · API: Importing existing assets
Clarifying Hacker Profile “About me” and “Intro” fields
Both free-text fields on the hacker profile settings page now carry persistent helper text explaining exactly where their content appears on the public profile.
What we did:
Added always-visible helper text under each field:
About me - appears under your profile picture and next to your name on the leaderboard
Intro - appears at the top of your profile, directly above Hacktivity
Each line also states its character limit and whether Markdown is supported.
Why we did it:
Hackers told us that they couldn't tell where "About me" went. Both fields are public, but their labels read as inverted relative to their output; the field labeled "Intro" produces the profile section headed "About {name}", while "About me" produces the short intro line.
Who it helps:
Hacker editing their profile, particularly newer hackers setting one up for the first time.
Spot Check deadlines now show days, hours, and minutes
The Due in column on a researcher's Spot Checks page now counts down in hours and minutes once a deadline is less than a day away, instead of showing "0 days" for the final 24 hours.
What we did:
Due in now picks its unit from the time actually remaining: 6 days, 1 day, 18 hours, 45 minutes, Less than a minute. Values always round down, so the column never overstates the time left. Multi-day countdowns are unchanged.
Why we did it:
For the entire last day before a deadline, the column read "0 days", which was ambiguous enough to be read as "the window has closed". It was least informative when it mattered most, and a missed submission deadline forfeits the reward.
Who it helps:
Researchers with an accepted Spot Check. This was a feature Request raised by the Hacker Success Program.
How to use it:
Nothing to enable. Visible automatically on the Accepted tab of My Spot Checks for anyone with an accepted Spot Check.


