INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Mythos Era Bug Bounty Program Exploited by Lazarus Group

| 2026-06-11 00:00 HIGH LOW EXPLOITED VULNERABILITY STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A bug bounty submission was received by the company shortly after related materials were published, with a suspiciously timed submission from researchers at Code White in Germany. The researcher claimed to be based in Japan but their device's IP location was geolocated to China, where the epicenter of Pacific Rim activity is identified as being located. This incident affected 7,091 total submissions and resulted in one vulnerability being discovered, with a reward paid out for this specific finding. The attack works by utilizing AI-assisted research tools that flood programs with low-signal 'slop', while also producing validated vulnerabilities at machine speed. As of the writing date, the company has paid out $599,695 in rewards for 1,343 vulnerabilities discovered through their bug bounty program since its launch on December 14, 2017.
Technical Mitigations AI-generated
• Use validated, reproducible exploit hypotheses to improve the effectiveness of bug bounty programs. • Implement techniques that reason across codebases and build non-obvious chains to detect vulnerabilities at machine speed. • Block or hunt for low-effort, AI-assisted submissions with a high false positive rate.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2022-1040CVE-2022-1040 CVE-2020-15504CVE-2020-15504 CVE-2020-12271CVE-2020-12271
Target & Sectors
NORTH_AMERICA NORTH_AMERICA DACH DACH
Incident Timeline
‎December 14, 2017
Threat actors submitted 7,091 vulnerabilities to the Mythos era bug bounty program between December 14, 2017 and this writing.
financial $599,695 rewards
‎June 2020
Firmware 18.0 MR1-1 was released in June 2020 with a built-in fix, addressing an issue that occurred prior to its release date.
infrastructure 18.0
‎July 2020
A researcher claiming to be based in Japan submitted a zero-day vulnerability, CVE-2022-1040, to the bug bounty program one day before it was actively exploited.
infrastructure 17.5
infrastructure 13.07.2020
financial $20,000 $ bounty
‎January 2026
Researchers at Code White, a Germany-based security company, submitted a SQLi (CVE-2020-15504) vulnerability report through the program that could have been leveraged for RCE.
infrastructure Windows
financial $80,000 $ Sophos Central
financial $8,000 $ targets
infrastructure 21.05.2020
financial $9,600 Endpoint
financial $2,000 report
financial $11,650 Central
financial $5,500 reward
financial $21,500 Firewall
‎2026/06/11
Threat actors exploited a previously unknown SQLi (CVE-2020-12271) leading to RCE on some firewall products.
infrastructure Windows
financial $80,000 $ Sophos Central
financial $50,000 $ Sophos Firewall
financial $8,000 $ targets
financial $5,000 $ Intercept X Endpoint
financial $59,400 numbers
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
financial
80,000
$ Sophos Central
Metrics
financial
50,000
$ Sophos Firewall
Metrics
financial
8,000
$ Targets
Metrics
financial
5,000
$ Intercept X Endpoint
Metrics
financial
59,400
Numbers
Metrics
infrastructure
‎21.05.2020
Software Version
Metrics
infrastructure
‎18.0
Software Version
Metrics
infrastructure
‎17.5
Software Version
Metrics
infrastructure
‎13.07.2020
Software Version
Metrics
financial
9,600
Endpoint
Metrics
financial
2,000
Report
Metrics
financial
11,650
Central
Metrics
financial
5,500
Reward
Metrics
financial
21,500
Firewall
Metrics
financial
599,695
Rewards
Metrics
financial
20,000
$ Bounty
Intelligence Sources
Sophos News 2026-06-11
Sophos News 2026-06-11