<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Bug-Bounty on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/bug-bounty/</link><description>Recent content in Bug-Bounty on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Tue, 18 Jun 2024 15:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/bug-bounty/index.xml" rel="self" type="application/rss+xml"/><item><title>Google Denies Bug Bounty for Unpatched Flaw: What It Means</title><link>https://zxcloudsecurity.co.uk/posts/google-bug-bounty-denied-unpatched-flaw-working-as-intended/</link><pubDate>Thu, 18 Jun 2026 15:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/google-bug-bounty-denied-unpatched-flaw-working-as-intended/</guid><description>Google praised a researcher for finding a security flaw, then denied the bug bounty and left it unpatched. Here&amp;#39;s what cloud architects need to know.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/18/google-told-researcher-nice-catch-then-denied-bug-bounty-for-flaw-it-still-hasnt-fixed/5258076">The Register — Security</a></p>
<hr>
<p>A security researcher discovered a vulnerability in a Google product, received praise from the company, but was denied a bug bounty payment after Google classified the flaw as &lsquo;working as intended.&rsquo; The issue reportedly remains unpatched, raising concerns about how Google handles responsible disclosure and researcher compensation. This case highlights ongoing tension between bug bounty programmes and vendors&rsquo; willingness to acknowledge and remediate reported flaws.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Do not assume a vendor&rsquo;s bug bounty acknowledgement equates to remediation — independently track reported vulnerabilities in your GCP or Google Workspace environments and apply compensating controls until a fix is confirmed. Review your third-party risk processes to account for unpatched vendor-classified &lsquo;by design&rsquo; flaws.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/18/google-told-researcher-nice-catch-then-denied-bug-bounty-for-flaw-it-still-hasnt-fixed/5258076">Google told researcher &lsquo;Nice catch!&rsquo; Then denied bug bounty for flaw it still hasn&rsquo;t fixed</a></p>
]]></content:encoded></item></channel></rss>