Wanted: Bug Hunters for Adobe’s Live Bug Bounty Meetup at Nullcon Goa!

Feb 28, 6:00 AM – Mar 2, 9:30 AM (UTC)

Sponsored Conferences & Events

Are you ready to showcase your skills, collaborate with fellow experts, and help secure the digital experience of millions around the globe? Adobe is inviting talented security researchers to NullCon to participate in an exciting live bug bounty event. You’ll have the opportunity to identify real vulnerabilities, earn rewards, and contribute to securing Adobe’s products.

Sponsored Conference

Read More & Request an Invite

*Limited seats to only registered conference attendees. If you are interested to get the invite for this private event, then fill the form linked above. Kindly note, only 50 candidates would be selected for this Live Bug Hunting Meetup.

About this event!

Are you ready to showcase your skills, collaborate with fellow experts, and help secure the digital experience of millions around the globe? Adobe is inviting talented security researchers to NullCon to participate in an exciting live bug bounty event. You’ll have the opportunity to identify real vulnerabilities, earn rewards, and contribute to securing Adobe’s products.

The event kicks off online on February 28 at 11:30AM, 1 day before NullCon. It will culminate on March 2 at 3PM during the conference, where special prizes for TWO researchers who submit the “best vulnerability” and “most creative” report will be awarded.

How to Participate: 

1. You must create a HackerOne account and submit all reports through Adobe’s Bug Bounty program. Sign up at: https://hackerone.com/adobe.

2. Read the instructions and register at https://nullcon.net/goa-2025/live-bug-hunting

*Limited seats to only registered NullCon conference attendees. If you are interested to get the invite for this private event, then fill up the form linked above. Kindly note, only 50 candidates would be selected for this Live Bug Hunting

Rules of Engagement

  • Please use your own account for testing or research purposes. Do not attempt to gain access to another user’s account or confidential information.

  • Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue may not be marked as triaged.

  • Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.

  • When duplicates occur, we only triage the first report that was received (provided that it can be fully reproduced).

  • Multiple vulnerabilities caused by one underlying issue will be treated as one valid report.

  • Social engineering (e.g. phishing, vishing, smishing) is prohibited.

  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.

  • Please do not test for spam, social engineering, or denial of service issues.

  • Please do not engage in any activity that can potentially or actually cause harm to Adobe, our customers, or our employees.

  • Do not engage in any activity that violates (a) federal or state laws or regulations or (b) the laws or regulations of any country where (i) data, assets, or systems reside, (ii) data traffic is routed, or (iii) the researcher is conducting research activity.

  • Do not store, share, compromise, or destroy Adobe or customer data. If Personally Identifiable Information (PII) is encountered, you should immediately halt your activity, purge related data from your system, and immediately contact Adobe. This step protects any potentially vulnerable data, and you.

Scope

PLEASE READ:

  • Some vulnerabilities are out of scope for the meetup. Please review the full list in the “Program exclusions” section of the policy page along with the testing plan for each product in scope before submitting any reports.

  • Submit your bug report with code: NULLCONLIVE2025 (Code expires March 3, 2025) to earn an additional 10% bounty on your bug reports against Adobe Learning Manager or ColdFusion.

  • At the end of NullCon on March 2, Adobe will award a 1 YEAR CREATIVE CLOUD SUBSCRIPTION to the researcher who has submitted the “most creative vulnerability” and APPLE AIRPODS PRO 2 to the researcher who has submitted the “best vulnerability” during the live bug bounty meetup. The two winners will receive an email at the end of the day.

  • Every valid report will earn Hall of Fame points: https://helpx.adobe.com/security/security-researcher-hall-of-fame.html

  • See more details of the competition rules here: https://acrobat.adobe.com/id/urn:aaid:sc:VA6C2:1df8f1ba-dd73-4dc4-818e-d4be77736737.

When

When

February 28 – March 2, 2025
6:00 AM – 9:30 AM (UTC)

Contact Us