333 of 543 S&P 500 companies (61.3%) serve live HTTPS with zero HSTS header — 10,314 host findings.
323 of those 333 (97.0%) have no HackerOne bounty coverage.
Palo Alto Networks (a security vendor) has 118 such hosts, unreported to anyone.
nullblocks.com/blog/missing-h…
Reverse WHOIS turned up 840 real sister domains across 25 S&P 500 companies. 19 of those 25 have zero HackerOne bounty coverage anywhere.
Workday's myworkday.com alone carries 3 CRITICAL/CVSS-10.0 CVEs with no bounty coverage on file.
nullblocks.com/blog
Still finding .DS_Store files in web roots in 2026. macOS quietly writes one to every folder, and it leaks a full directory listing if the server serves it.
4 exposure classes scanned across the S&P 500. Same pattern every time:
Takeover: 23/24 no bounty coverage
GraphQL: 22/24 no coverage
Wayback legacy: 95/103 no coverage
Critical CVEs: 330/341 no coverage
Not a one-off stat. Structural.
nullblocks.com/blog
JARM fingerprints cluster servers by TLS handshake behavior, not certs or IPs. Two totally unrelated domains sharing a JARM hash usually means same infra.
157 of 543 S&P 500 companies (28.9%) serve live traffic on a host with an expired TLS cert. Dell's b2bsas2.dell.com cert expired 2015-01-27, 4,225 days ago, still answering. 6th independent exposure class, same gap. nullblocks.com/blog/expired-t…
17K Followers 842 Following🔍 Top 70 Bug Bounty Hunter @ Bugcrowd | 🇩🇴 Dominican | Ethical hacking fanatic | 🎮🎵 Lover | Keeping the digital world safe. opinions are that of my own
69K Followers 2 FollowingThis is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD
56K Followers 618 FollowingGrzegorz Niedziela - a hacker who documents his hacking journey by creating and curating the best content about bug bounty and offensive security.
48K Followers 515 Followinghacker; head of offensive ai @wiz_io, now at @google; post-training, gemini cyber & agentic pentesting; $3,000,000 bug bounty hunter; arsenal