Pentagon Looking For A Few Good Hackers
Cash rewards await white hat hackers in an experimental bug bounty program launched on American Independence Day by the U.S. Department of Defense.
The Pentagon has tinkered since 2016 with accepting vulnerability reports from security researchers, recently crediting researchers with the closure of more than six thousand vulnerabilities on public-internet facing military IT systems during 2021, alone.
This newest pilot program, launched with vulnerability disclosure partner HackerOne, isn't the first time the military has offered to pay researchers for exploits, but it is the first to contemplate offering continuous rewards, the San Francisco-based company tells Information Security Media Group. The pilot program has a cash pool of $110,000, with $75,000 earmarked for first-submitted, first-awarded high and critical severity findings, and $35,000 kept for awards such as the best finding on the army.mil domain.