$50K at 15: Zendesk Bug Bounty Drama, White Hats & Weak Links episode artwork

EPISODE · Apr 8, 2025 · 29 MIN

$50K at 15: Zendesk Bug Bounty Drama, White Hats & Weak Links

from SEEK Bytes · host SEEK

What happens when a 15-year-old hacker quietly discovers a single bug that touches over half of the Fortune 500, chains it into a Slack takeover, and walks away with $50K in bug bounties – only for the original vendor to refuse to pay? In this episode of SEEK Bytes, we break down Daniel’s Zendesk exploit, the ethics of disclosure, and what “white hat” really means in practice. We unpack how a “basic” support inbox ([email protected]), misconfigured SSO and email spoofing turned into a way to join internal tickets, steal Slack access and read sensitive conversations – all via a third-party tool many enterprises barely think about. We also dig into how bug bounty programs work, why Zendesk’s scope call sparked controversy, and how SEEK runs security exercises to stay ahead of attackers. In this episode you’ll learn: • How the exploit actually worked end-to-end – from Zendesk ticket IDs and CC’ing yourself onto “internal” threads, to chaining Apple/Google OAuth and Slack login for access to private workspaces. • Why the bug bounty outcome was so controversial – how email-spoofing being “out of scope” left Daniel unpaid by Zendesk, and what this means for incentivising white-hat behaviour vs pushing hackers towards greyer choices. • Practical security takeaways for engineers – the real risk of “weakest link” third-party tools, why internal channels are goldmines for social engineers, and how separation of concerns and well-designed bounties can protect both your systems and your customers. Whether you’re in software engineering, security, cloud, support, architecture or IT leadership, this episode is a gripping case study in modern attack chains, bug bounty programs and why “it’s just email” or “it’s just a ticketing tool” is never the whole story. 👍 Follow the SEEK Bytes podcast so you never miss a new episode

What happens when a 15-year-old hacker quietly discovers a single bug that touches over half of the Fortune 500, chains it into a Slack takeover, and walks away with $50K in bug bounties – only for the original vendor to refuse to pay? In this episode of SEEK Bytes, we break down Daniel’s Zendesk exploit, the ethics of disclosure, and what “white hat” really means in practice. We unpack how a “basic” support inbox ([email protected]), misconfigured SSO and email spoofing turned into a way to join internal tickets, steal Slack access and read sensitive conversations – all via a third-party tool many enterprises barely think about. We also dig into how bug bounty programs work, why Zendesk’s scope call sparked controversy, and how SEEK runs security exercises to stay ahead of attackers. In this episode you’ll learn: • How the exploit actually worked end-to-end – from Zendesk ticket IDs and CC’ing yourself onto “internal” threads, to chaining Apple/Google OAuth and Slack login for access to private workspaces. • Why the bug bounty outcome was so controversial – how email-spoofing being “out of scope” left Daniel unpaid by Zendesk, and what this means for incentivising white-hat behaviour vs pushing hackers towards greyer choices. • Practical security takeaways for engineers – the real risk of “weakest link” third-party tools, why internal channels are goldmines for social engineers, and how separation of concerns and well-designed bounties can protect both your systems and your customers. Whether you’re in software engineering, security, cloud, support, architecture or IT leadership, this episode is a gripping case study in modern attack chains, bug bounty programs and why “it’s just email” or “it’s just a ticketing tool” is never the whole story. 👍 Follow the SEEK Bytes podcast so you never miss a new episode

NOW PLAYING

$50K at 15: Zendesk Bug Bounty Drama, White Hats & Weak Links

0:00 29:28

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

SPADE: The Podcast Paul Anthony Henderson Jr SPADE: The Podcast stands as a beacon of hope and understanding, addressing critical mental health challenges within the African American community. SPADE (Suicide, Post-Traumatic Stress Disorder, Anxiety, Depression, and Epilepsy) seeks to shine a light on topics often stigmatized and misunderstood. Our mission is to break the silence surrounding these issues, encouraging open dialogue and fostering a culture of support and education. By providing meaningful resources and sharing powerful stories, we aim to empower individuals to confront these challenges head-on and build pathways toward healing. Mental health is a crucial but often overlooked subject in the African American community. It’s time to dismantle the barriers of shame and stigma, ensuring everyone feels safe to speak their truth and seek the help they need. This podcast is more than just a platform—it’s a movement to spark change, spread awareness, and inspire action within families, friendships, and communities. Focus on Nutrition and Nutrition Science ReachMD Ever-increasing evidence points to the importance of nutrition in preventing and managing disease. Through a thorough examination of metabolic and physiological responses of the body to diet and nutrition, we seek to highlight current topics, research and best practices in this field. The Johnny Vedmore Show TNT News Johnny Vedmore follows the tentacles of the new world beast. Especially during an election year, it’s vital we know who are the allies and associate of those who officially represent us.The show will look at the associations of those in the news, from Palestine to Ukraine, from Westminster to the White House, marrying deep research with current affairs.It will analyse the current news with deep context, informing the viewers of the little known allegiances of those who seek power and influence over our lives.The guests will help define and explain the many tentacles of the Establishment Octopus.

Frequently Asked Questions

How long is this episode of SEEK Bytes?

This episode is 29 minutes long.

When was this SEEK Bytes episode published?

This episode was published on April 8, 2025.

What is this episode about?

What happens when a 15-year-old hacker quietly discovers a single bug that touches over half of the Fortune 500, chains it into a Slack takeover, and walks away with $50K in bug bounties – only for the original vendor to refuse to pay? In this...

Can I download this SEEK Bytes episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!