A 15-year-old bug hunter discovered a vulnerability in Zendesk that allowed attackers to read customer support tickets from any company using the platform. The bug was initially reported to Zendesk through their bug bounty program, but was rejected as out of scope. The bug hunter then used the vulnerability to exploit a Slack takeover, which was later fixed by Zendesk. The bug hunter earned over $50,000 in bounties from individual companies, but Zendesk refused to award a bounty.