People who found something in SimpleSecurity and told us instead of anyone else.
This page is empty because the event has not run yet — not because nothing has ever been found. When someone reports a qualifying issue and wants the credit, their name goes here along with what they found and when we fixed it.
Read the event rulesCredit is opt-in and yours to shape. Tell us in your report how you want to appear — full name, handle, company, or a link — or ask to stay anonymous and we will simply record that an external researcher reported it.
We publish what class of issue was found and roughly when, never the working exploit, and never before it is fixed. If you would like your entry changed or removed later, email us and it is done — no argument, no conditions.