Inscrivez-vous maintenant pour un meilleur devis personnalisé!

Zoom awarded $1.8 million in bug bounty rewards over 2021

07 avr. 2022 Hi-network.com

Zoom has awarded$1.8 million to researchers who submitted bug bounty reports over 2021. 

Recommends

The best security key

While robust passwords help you secure your valuable online accounts, hardware-based two-factor authentication takes that security to the next level.

Read now

Bug bounty programs, whether private and available to invitees-only or public, where anyone can submit a vulnerability report, have become a critical method for organizations to improve their security posture. 

The industry is beset with talent shortages. Estimates suggest that there will be approximately 3.5 million unfilled job openings by 2025 in the US alone, and until there are more specialists available, companies often can't just rely on in-house security teams, who have more than enough of a workload. 

This is where bug bounties come in: external researchers and bug hunters can perform tests on software and services, report any severe security issues, and receive credit and/or financial rewards in return. 

The popularity of Zoom's teleconferencing video software exploded overnight due to COVID-19 and lockdowns, with many of us forced to work from home. However, the rapid increase in users also highlighted security problems that had to be addressed quickly. Hence, a bug bounty program was one of the firm's initiatives for improving the situation. 

Zoom's main program is private, but the platform actively recruits security researchers. Over 800 researchers participate in the program, which HackerOne hosts. 

Over 2021, the software vendor has paid out over$1.8 million across 401 reports. In addition, since the program's launch, over$2.4 million has been awarded. 

Zoom

Recent updates to the program include extending the bug bounty reward range on offer, with up to$50,000 per report for the most severe vulnerabilities and$250 for low-hanging fruit. 

The company also launched a public Vulnerability Disclosure Program (VDP) and a VIP bug bounty program for licensed software. 

"While Zoom tests our solutions and infrastructure every day, we know it's important to augment this testing by tapping the ethical hacker community to help identify edge-case vulnerabilities that may only be detectable under certain use cases and circumstances," Zoom commented.  

See also

  • The complete Zoom guide: From basic help to advanced tips and tricks
  • Zoom live avatars: Finally, you can turn up to your meetings as a rabbit or a dog. Here's how
  • Take your Zoom meetings to the next level

Have a tip?Get in touch securely via WhatsApp Signal at +447713 025 499, or over at Keybase: charlie0


Security

8 habits of highly secure remote workersHow to find and remove spyware from your phoneThe best VPN services: How do the top 5 compare?How to find out if you are involved in a data breach -- and what to do next
  • 8 habits of highly secure remote workers
  • How to find and remove spyware from your phone
  • The best VPN services: How do the top 5 compare?
  • How to find out if you are involved in a data breach -- and what to do next

tag-icon Tags chauds: technologie La sécurité

Copyright © 2014-2024 Hi-Network.com | HAILIAN TECHNOLOGY CO., LIMITED | All Rights Reserved.