Muster.
← Case studies
Bug bounty acceptedUber

Muster discovered a vulnerability in Uber and earned a bug bounty

The Muster engine independently identified an infrastructure vulnerability exposing sensitive internal assets across Uber's attack surface, reported it through their bug bounty program, and received official recognition and a bounty award.

Bounty awarded

100%

Autonomous discovery

0

Manual intervention

The target

Uber Technologies operates one of the world's largest technology platforms, connecting millions of riders, drivers, and merchants across 70+ countries.

With a sprawling infrastructure spanning thousands of services and subdomains, Uber maintains one of the industry's most competitive bug bounty programs, attracting elite security researchers worldwide and setting a high bar for accepted submissions.

Powered by the Muster engine

This vulnerability was discovered end-to-end by the Muster engine, from attack surface reconnaissance and subdomain enumeration through infrastructure analysis and vulnerability identification, without manual researcher intervention.

Fully autonomous discovery

How it happened

1

Attack surface mapping

Muster autonomously enumerated Uber's publicly accessible infrastructure, mapping subdomains, services, and cloud storage endpoints across their sprawling digital footprint.

2

Infrastructure exposure detection

The AI analysis engine identified a misconfigured service exposing sensitive internal assets that should not have been publicly accessible, flagging it as a high-confidence finding.

3

Automated validation and report generation

The system confirmed the exposure, assessed the scope of accessible internal artifacts, and autonomously generated a detailed disclosure report with evidence and reproduction steps.

4

Responsible disclosure and bounty award

The vulnerability was reported through Uber's official bug bounty program. Uber's security team confirmed the finding and awarded a bounty.

Vulnerability confirmed by Uber's security team

Uber's security team reviewed and accepted the submission through their official bug bounty program. The vulnerability details remain confidential under responsible disclosure guidelines.

What this means

This bug bounty proves that the Muster engine can find real vulnerabilities in production systems at the highest level of the technology industry, across cloud infrastructure, web applications, and APIs. Muster autonomously discovered, validated, and reported a finding that Uber's security team confirmed.

This is Uber, one of the most scrutinized platforms in the world. The autonomous report was thorough, the reproduction steps were precise, and Uber's team confirmed it. We've built a system that finds real vulnerabilities in real production infrastructure, at the same level as elite human researchers.
NJNabeel JavedSecurity Researcher, Muster

Why Muster

Full-spectrum autonomous security

Cloud infrastructure, web applications, and APIs, not limited to any single domain.

Production-validated

Proven against some of the world's largest and most secure technology platforms.

Responsible disclosure built in

Automated report generation with evidence and reproduction steps for immediate actionability.

Continuous operation

The system works around the clock, mapping attack surfaces and identifying exposures at a scale no manual team can match.

Know your full attack surface.

The same engine that found this can run against your app. First exploits in about 10 minutes, free.

Start free pen test →

reported April 2026 · findings via public bug-bounty programs · not affiliated with these companies