Security News

Zoom Revamps Bug Bounty Program
2020-04-16 14:25

Zoom announced on Wednesday that it has teamed up with Katie Moussouris' company, Luta Security, to revamp its bug bounty program. Zoom announced on April 1 that it would be making significant changes to its bug bounty program, after experts raised concerns about Zoom security and researchers reported finding potentially serious vulnerabilities in the video conferencing service.

Tencent Ups Top Bug-Bounty Award to $15K
2020-04-15 16:17

The Tencent Security Response Center is launching an expanded bug-bounty program, via the HackerOne white-hat platform - and the company has increased its top reward to $15,000. Tencent, a China-based global internet service provider, is opening up its existing bug-bounty program to HackerOne's community of 600,000+ bug hunters, to widen the company's vulnerability reporting and technical sharing efforts, it said in a launch notice on Tuesday.

Tencent Partners With HackerOne for Bug Bounty Program
2020-04-15 04:20

HackerOne announced on Tuesday that the bug bounty program of Chinese technology giant Tencent is now accessible through its platform. More than 600,000 hackers registered on HackerOne can join Tencent's bug bounty program to hunt for vulnerabilities in the company's products.

Bug Bounty Programs Are Being Used to Buy Silence
2020-04-03 11:21

Used properly, bug bounty platforms connect security researchers with organizations wanting extra scrutiny. CSO's investigation shows that the bug bounty platforms have turned bug reporting and disclosure on its head, what multiple expert sources, including HackerOne's former chief policy officer, Katie Moussouris, call a "Perversion."

Katie Moussouris: The Bug Bounty Conflict of Interest
2020-02-12 14:37

Since the launch of the Hack the Pentagon program in 2016, bug bounty programs continue to increase in popularity - however, as more programs are created, some companies are forgetting the real reason behind bug bounties. Instead of aiming to make their systems more secure, companies are viewing bug bounty programs as a "One size fits all" solution for their business.

Facebook Paid $2.2 Million in Bug Bounty Rewards in 2019
2020-02-10 13:44

Over the course of 2019, Facebook paid security researchers a total of $2.2 million in rewards for vulnerability reports submitted to the social media platform's bug bounty program. For comparison, the social platform paid more than $1.1 million for over 700 valid reports submitted to its bug bounty program in 2018, and more than $880,000 for over 400 valid reports in 2017.

Dropbox Passes $1M Milestone for Bug-Bounty Payouts
2020-02-06 12:00

To mark the occasion, Dropbox also revealed details on a handful of older, resolved bugs for the first time. The issue involved a feature for Dropbox Professional and Business users that allows them to password-protect their shared links via an option in Link Settings.

The Rise of the Open Bug Bounty Project
2020-02-06 08:05

Today, Open Bug Bounty already hosts 680 bug bounties, offering monetary or non-monetary remuneration for security researchers from over 50 countries. Global companies such as Telekom Austria, Acronis, or United Domains run their bug bounties at Open Bug Bounty.

The Rise of the Open Bug Bounty Project
2020-02-06 00:05

Today, Open Bug Bounty already hosts 680 bug bounties, offering monetary or non-monetary remuneration for security researchers from over 50 countries. Global companies such as Telekom Austria, Acronis, or United Domains run their bug bounties at Open Bug Bounty.

Dropbox Paid Out Over $1 Million Through Bug Bounty Program
2020-02-04 17:52

File hosting company Dropbox says it has awarded researchers over $1 million for vulnerabilities reported through its bug bounty program. Dropbox launched its bug bounty program in 2014 and in April 2015 it announced a program on the HackerOne platform.