Creating a More Altruistic Bug Bounty Program

David Jacoby and Frans Rosén said at this year’s Security Analyst Summit they offered companies free pen-testing and raised $15,000 for charity in the process. Continue reading Creating a More Altruistic Bug Bounty Program

Katie Moussouris on Bug Bounty Programs, Hack the Army, and Wassenaar

Katie Moussouris on how bug bounty programs have gone mainstream, the success of Hack the Pentagon and Hack the Army, and where things stand with the Wassenaar Arrangement. Continue reading Katie Moussouris on Bug Bounty Programs, Hack the Army, and Wassenaar

Threatpost News Wrap, September 16, 2016

The news of the week is discussed, including Schneier’s DDoS article, a patched IE/Edge zero day, a new OS X malware detection method, and Google’s Project Zero prize. Continue reading Threatpost News Wrap, September 16, 2016

Putting Apple Bug Bounty Rewards in Perspective

Competing zero-day acquisition programs pay out much more than Apple’s new bug bounty program, but researchers used to submitting bugs gratis to Apple aren’t complaining much. Continue reading Putting Apple Bug Bounty Rewards in Perspective