YYaaa News

Xiaomi publicly names white-hat for unauthorized intrusion | MiSRC's first named public callout

TL;DR

Xiaomi Security Response Center on July 20 publicly disclosed: while handling a large-scale business intrusion on June 26, it found a white-hat surnamed Liu had submitted a vulnerability report via MiSRC while actually carrying out unauthorized intrusion beyond the scope. Xiaomi revoked all rewards, excluded the findings from honors/rankings, publicly named the incident, and reserved the right to pursue legal action.

Xiaomi Security Center on July 20 published a disclosure — while handling a large-scale business intrusion incident on June 26, it found that a white-hat surnamed Liu submitted a vulnerability report via MiSRC (Xiaomi Security Response Center), but investigation determined the activity was not a compliant bug hunt but actual illegal intrusion, crossing the authorized security testing scope.

The penalty has three parts: revoke all rewards for this submission; exclude the findings from any honor or ranking; and publicly disclose the incident. Xiaomi said the behavior violated the MiSRC Vulnerability Reward Program Rules V10.0 and reserved the right to pursue legal action.

It's MiSRC's first named public callout of an individual — past disclosures at most said "a white-hat had rewards revoked for violations," without naming the surname. Public naming plus reserved legal recourse suggests Xiaomi believes the unauthorized activity crossed criminal thresholds, though it's holding legal action for now.

The tension is in the gray zone — a white-hat's authorization boundary in SRC programs is drawn by "scope + method" as a sandbox. Business-side production intrusion is usually explicitly excluded, but hunters often stumble into fuzzy territory. Xiaomi's classification of "large-scale business intrusion" as substantially illegal sets a new industry boundary warning.

Reactions from China's SRC community are split — some think Xiaomi upheld the rules, others think this makes SRC authority entirely one-sided in favor of vendors, sharply raising risk for white-hats.

via Sohu
小米通報白帽越權入侵|取消獎金並保留追責,MiSRC 首例公開通報