Security News

Facebook Announces Bug Bounty Loyalty Program, Streamlined Bug Triage
2020-10-12 18:27

Facebook has announced a series of updates for its bug bounty program, including bonus rewards for engaged researchers, as well as a faster bug triage process. The social media platform announced that it streamlined the triage of security vulnerabilities reported through its bug bounty program, to increase efficiency and lower response timeframe.

Facebook Debuts Bug-Bounty ‘Loyalty Program’
2020-10-09 14:50

Facebook has lifted the curtain on what it claims is an industry first: A loyalty program as part of its bug-bounty offering, which aims to further incentivize researchers to find vulnerabilities in its platform. The loyalty program, called "Hacker Plus," offers bonuses on top of bounty awards, access to more products and features that researchers can stress-test, and invites to Facebook annual events.

Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers
2020-10-08 22:40

If you're designing a security bug bounty for your organization's products, by all means get the lawyers to take a look, but keep their hands off the keyboard. Chloé Messdaghi, veep of strategy at infosec training firm Point3, said she's encountered bounty programs that look more like they're intended for the legal team than the security community.

Grindr’s Bug Bounty Pledge Doesn’t Translate to Security
2020-10-06 19:44

Grindr isn't alone - many companies are looking to adopt, or have already adopted, bug-bounty programs or vulnerability-disclosure programs. It's important to distinguish the two: A bug-bounty program offers cash rewards for finding flaws, while a VDP covers when a vulnerability is reported by a third party to an organization.

HP expands its Bug Bounty Program to focus on office-class print cartridge security vulnerabilities
2020-10-02 03:30

HP has expanded its Bug Bounty Program to focus specifically on office-class print cartridge security vulnerabilities. As part of this program, HP has engaged with Bugcrowd to conduct a three-month program in which four professional white hat hackers have been challenged to identify vulnerabilities in HP Original print cartridges.

Bug Bounty FAQ: Top Questions, Expert Answers
2020-09-26 10:01

Threatpost brought together leading voices in the bug bounty community to participate in a webinar Five Essentials for Running a Successful Bug Bounty Program. Are the hackers getting legal advice before engaging in these programs or are you relying on the bug bounty programs to keep them within in the legal lines?

It's been a vintage year for bug bounty hunters, says HackerOne as it boasts of $40m+ passing through its treasure chests
2020-09-22 21:06

Bounty-hunting hackers are uncovering new vulnerabilities every two minutes on average, according to bug bounty platform HackerOne. "Mickos rejected the idea that ethical hackers deprived of a legitimate bug bounty market would instead sell newly discovered vulnerabilities to black hats for exploitation, saying:"If we didn't organise this program, the vulnerabilities would not be sold to criminals.

Google Increases Bug Bounty Payouts for Abuse Risk Flaws
2020-09-02 21:23

Google this week increased the reward amounts paid to researchers for reporting abuse risk as part of its bug bounty program. Google added product abuse risks to its Vulnerability Reward Program two years ago and says that more than 750 such issues have been identified since.

FireEye Launches Public Bug Bounty Program on Bugcrowd
2020-08-13 10:23

FireEye this week announced that its Bugcrowd-powered bug bounty program has become public, for all registered researchers to participate. The program, which has been running privately on the crowd-sourced bug hunting platform for a while, welcomes all Bugcrowd researchers interested in identifying vulnerabilities in a broad range of FireEye websites, including those of subsidiaries and localized domains.

Microsoft Paid Out Nearly $14 Million via Bug Bounty Programs in Past Year
2020-08-04 16:08

Microsoft reported on Tuesday that it paid out roughly $13.7 million through its bug bounty programs between July 1, 2019, and June 30, 2020. The tech giant runs 15 bug bounty programs, which 327 researchers used in the past year to report 1,226 eligible vulnerabilities.