upvote
Seems similar to what Microsoft is doing lately:

https://www.cpomagazine.com/cyber-security/microsoft-doubles...

reply
That's actually very common even with respected bug bounty programs. Communicating exploits to anyone else (let alone the general public) will at the very least make you ineligible for rewards.
reply
IMO if you're participating in a BB program, you should abide by he rules set forth by the program.

If you're not, then you don't have to.

reply