As companies have shifted to a cloud-first architecture and adopted continuous deployment and DevOps practices the exposed attack surfaces of these organisations have become more fluid and evolve rapidly. This pace has exposed new types of vulnerabilities and security issues including those that are ephemeral in nature but often have critical security impact and static, point in time security assessment is failing to keep up. This presentation will explore our research into ephemeral application security vulnerabilities and our experience applying this to real world environments through bug bounties. Specifically we will detail how ephemeral application security vulnerabilities are introduced and explore methods and techniques to find ephemeral vulnerabilities with detailed examples of critical ephemeral issues found when applying our research to bug bounty programs. We will also present the case for continuous application security assessment as well as strategies and techniques that organisations can apply to prevent these issues.