Skip to main content

Changelog 2026-07

[CORE] YesWeHack credits

Key changes

A new submission model has been implemented in the platform. The current submission constraint (‘Accepted, Duplicate, Resolved’ reports’ ratio) has been replaced with a new credit-based system for submitting vulnerability reports on Bug Bounty and Featured VDP programs.

Each program now requires a specific number of credits to submit a report. Hunters recover the credits they spent when their report is accepted and receive a bonus. They can also earn an additional bonus based on the report's severity.

Impact

  • This feature helps limiting the number of low-quality reports submitted on the platform (e.g., AI-generated reports and spam)

  • Therefore, it reduces the time the triage team needs to assess vulnerability reports from serious Hunters.

Audience

  • All YesWeHack Hunters

  • All Bug Bounty and Featured-VDP programs

Usage

ℹ️ Learn more about the YesWeHack credits here.

As a Hunter,

  • Go to “My programs” where you can see the cost of a submission on each card

  • Open a Bug Bounty program

  • Each program includes a “Credits” section that displays the cost of a submission


[EM] Attack surface multi-programs

Key changes

Organisations can now create multiple attack surface programs to reflect their internal structure (e.g., teams, entities or subsidiaries) and set separate access rights for each program.

Impact

  • By enabling the creation of multiple attack surface programs, this feature helps organisations better manage their assets and reduces the risk of internal information leaks.

Audience

  • All Exposure Management and Continuous Pentesting customers

Usage

ℹ️ You must be a Business unit owner (BUO), a Business Unit Manager (BUM) or Business Unit Surface Manager (BUSM) to create a Surface program.

  • Go to “Admin Panel”

  • Click on “+ Surface”

  • Fill in the “Title” field

  • Click on “Create”

Your Surface program is now created. Add primary assets to complete your program.

ℹ️ Learn more about how to set up a Surface program here.


[MISC]

  • [Hunters] Hunters can now export a Bug Bounty program's scope list directly from each program card in the Admin Panel for use in their tools (e.g., Burp Suite).

Did this answer your question?