Security News

Newsmaker Interview: Marten Mickos the Future of Bug Bounty
2018-07-02 18:28

Mickos sat down with Threatpost's Lindsey O'Donnell to talk about bug bounty program opportunities, challenges, and ultimately how programs are evolving.

Bug Bounty Programs Turn Attention to Data Abuse
2018-07-01 19:19

More companies – particularly social media firms – may follow Facebook’s footsteps in turning to bug bounty programs to scout out any data privacy abuse on their platforms, experts say.

Facebook shells out $8k bug bounty after quiz web app used by 120m people spews profiles
2018-06-28 20:02

Infosec bod shops NameTests, claims leaky code exposes info Facebook has forked out an $8,000 reward after a security researcher flagged up a third-party web app that potentially exposed up to 120...

Facebook pays out $8,000 under data abuse bug bounty scheme
2018-06-28 20:02

Security researcher shops NameTests app as leaky javascript exposes user info Facebook has paid out $8,000 after a security researcher reported an app blabbing users’ info in what is possibly the...

Researchers claim Chrome bug bounty paid to the wrong people
2018-06-19 12:42

Yubico has been drawn into a rare public spat over how the discovery of a security flaw affecting it products was credited.

Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke
2018-06-18 23:21

USB gizmo biz apologies amid infosec drama Yubico has apologized to a security vulnerability researcher who had complained the dongle peddler lifted his work to nab a $5,000 Google bug bounty.…

Surprise! Student receives $36,000 Google bug bounty for RCE flaw
2018-05-23 12:38

What's the only thing better than a bug bounty reward? A bug bounty reward you weren't expecting. Especially one that's worth $36,337.

Uber Tightens Bug Bounty Extortion Policies
2018-04-27 17:16

Uber is tightening policies around its bug bounty program after a 2016 data breach exposed deep flaws in its policies around handling extortion.

HackerOne CEO Talks Bug Bounty Programs at RSA Conference
2018-04-20 13:03

Can bug bounty programs be designed to protect consumer privacy and how do programs balance white hat disclosure versus companies sitting on vulnerabilities until they are fixed?