TikTok, GitHub, Facebook Join Open-Source Bug Bounty
#1
Information 
Quote:Tech giants want hackers to their money, in exchange for rooting out critical vulnerabilities lurking in the open-source code they use.
 
As more businesses rely on open-source software for mission-critical infrastructure, HackerOne, along with sponsors including Elastic, Facebook, Figma, GitHub, Shopify and TikTok, announced they are throwing a new round of resources behind an Internet Bug Bounty Program (IBB) to lure threat hunters’ attention to open-source supply chains.
 
For perspective, recent research from Synopsys found the average application uses around 528 open-source components, and most of the high-risk vulns found last year had been around for more than two years — meaning they had plenty of time to proliferate. A 2020 review also found that 70 percent of mobile and desktop apps contain open-source bugs.
 
So far, the program has already made good progress. HackerOne initially launched the IBB back in 2013 and has since found 1,000 bugs and paid out $900,000 to around 300 hackers, the company said.
 
Following a spate of spectacular software supply-chain breaches, market leaders have decided to throw in some cash to fund the IBB to incentivize bug hunters to take a closer look at open-source code.
 
“Recent cyberattacks against software supply chains demonstrate the urgency of securing these organizational blind spots. And open-source software represents a growing portion of the world’s critical supply-chain attack surfaces,” Alex Rice CTO and co-founder of HackerOne said in the announcement. “The new IBB empowers organizations that are beneficiaries of open source to play an active role in collectively building more secure digital infrastructure for everyone.”

Read more: TikTok, GitHub, Facebook Join Open-Source Bug Bounty | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Trying out EaseUS Video Downloader Pro
This is a very g...masonwright757 — 21:58
XYplorer
XYplorer (64-bit) v2...jAcos — 17:39
RAM Booster for PC
harlan4096 — 10:23
RAM Booster for PC
Hello, Plz Sugges...alina104 — 09:34
Microsoft Retires Standalone SharePoint ...
Microsoft Is Ending...harlan4096 — 08:29

[-]
Birthdays
Today's Birthdays
avatar (49)zamokpluff
avatar (30)sarapelon21
avatar (51)FrankNub
Upcoming Birthdays
avatar (47)hapedDow
avatar (46)komriwat
avatar (48)Michaelecozy
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (50)neuthrusBub
avatar (30)script6027529171
avatar (46)delsreehRob
avatar (44)pyotrded
avatar (41)oecmecodo
avatar (40)ShakitaSmobe
avatar (49)tsorenHievy
avatar (46)myhotseeve
avatar (46)Edwinmub
avatar (46)dimaWeami
avatar (41)svoyaEnuct
avatar (39)TranoTymn
avatar (39)MezirLal
avatar (50)listfquoto
avatar (46)dima6sarPrave
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (41)yposegij
avatar (44)Baihu
avatar (27)RaseinsLikes

[-]
Online Staff
There are no staff members currently online.

>