Google launches new bug bounty platform
Vulnerability hunters will be able to improve their skills through the newly launched Bug Hunter University
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Google has announced the launch of a new bug bounty platform that will make it easier for vulnerability hunters to submit issues.
Available under bughunters.google.com, the platform brings together all of the tech giant’s vulnerability reward programmes (VRP) – Google, Android, Abuse, Chrome, and Play – with hunters able to submit issues using a single intake form.
Moreover, the new platform will provide more opportunities for interaction with other hunters through gamification, including awards and badges for certain bug-reporting achievements.
Google has also improved its VRP leaderboards, which will now be “more functional and aesthetically pleasing”, as well as show the best hunters per country, making it easier to use the results to boost a CV when applying for a job in tech.
The new platform also provides greater emphasis on research and education, making it easier for hunters to publish their bug reports in order to share their knowledge. Hunters will also be able to improve their skills through the newly-launched Bug Hunter University, which includes courses on how to submit a successful vulnerability report.
Research papers on the security of open source will be eligible for a reward, just like open source software patch submissions, while hunters improving security in open source programmes will be eligible to apply for a grant to better secure their own projects.
RELATED RESOURCE
Commenting on the announcement, Google VRP technical programme manager, Jan Keller, said that when Google launched its “very first VRP” over a decade ago, no one knew “how many valid vulnerabilities – if any – would be submitted on the first day”.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“Everyone on the team put in their estimate, with predictions ranging from zero to 20. In the end, we actually received more than 25 reports, taking all of us by surprise,” he added.
Three years later, the programme was expanded to include open source as well as Google Android and Apache.
“Since its inception, the VRP programme has not only grown significantly in terms of report volume, but the team of security engineers behind it has also expanded – including almost 20 bug hunters who reported vulnerabilities to us and ended up joining the Google VRP team. That is why we are thrilled to bring you this new platform, continue to grow our community of bug hunters and support the skill development of up-and-coming vulnerability researchers,” said Keller.
Having only graduated from City University in 2019, Sabina has already demonstrated her abilities as a keen writer and effective journalist. Currently a content writer for Drapers, Sabina spent a number of years writing for ITPro, specialising in networking and telecommunications, as well as charting the efforts of technology companies to improve their inclusion and diversity strategies, a topic close to her heart.
Sabina has also held a number of editorial roles at Harper's Bazaar, Cube Collective, and HighClouds.
-
Low-budget devices are the biggest casualty of the RAM crisisNews Say goodbye to budget devices; vendors are doubling down on high-end options to absorb costs
-
Sectigo taps Clint Maddox to lead global field operationsReviews The appointment follows a year of strong momentum for the security vendor as it expands its global channel footprint
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
Millions of developers could be impacted by flaws in Visual Studio Code extensions – here's what you need to know and how to protect yourselfNews The VS Code vulnerabilities highlight broader IDE security risks, said OX Security
-
CVEs are set to top 50,000 this year, marking a record high – here’s how CISOs and security teams can prepare for a looming onslaughtNews While the CVE figures might be daunting, they won't all be relevant to your organization
-
Microsoft patches six zero-days targeting Windows, Word, and more – here’s what you need to knowNews Patch Tuesday update targets large number of vulnerabilities already being used by attackers
-
Experts welcome EU-led alternative to MITRE's vulnerability tracking schemeNews The EU-led framework will reduce reliance on US-based MITRE vulnerability reporting database
-
Veeam patches Backup & Replication vulnerabilities, urges users to updateNews The vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds – but not previous versions.
-
Two Fortinet vulnerabilities are being exploited in the wild – patch nowNews Arctic Wolf and Rapid7 said security teams should act immediately to mitigate the Fortinet vulnerabilities
-
Everything you need to know about Google and Apple’s emergency zero-day patchesNews A serious zero-day bug was spotted in Chrome systems that impacts Apple users too, forcing both companies to issue emergency patches
