
A researcher responsibly disclosed multiple vulnerabilities to Slack that allowed an attacker to hijack a user's computer, and they were only rewarded a measly $1,750. Using these vulnerabilities, an attacker could simply upload a file and share with another Slack user or channel to trigger the exploit on a victim's Slack app.
Slack pays stingy $1,750 reward for a desktop hijack vulnerability
BleepingComputer






Galus Australis

Brave New Coin


ZDNet






