The United States Department of Defense (DoD) has launched a one-week bug bounty program to reward researchers who find high- and critical-severity vulnerabilities in publicly accessible assets owned by the DoD.
The new program, called Hack U.S., is a brief extension of the DoD’s vulnerability disclosure program (VDP) that runs on the HackerOne platform. It will be open between July 4 and July 11 to bug hunters and security researchers all over the world.
Here are the raw details from the DoD/HackerOne announcement:
From July 4th, 2022, to July 11th, 2022, High and Critical severity findings ONLY will be eligible for a bounty on any publicly accessible information systems, web property, or data owned, operated, or controlled by DoD.
The bounty pool for this engagement is $110,000 total. $75,000 will be allocated for vulnerability submissions on a first-submitted, first-awarded basis until that pool of $75,000 is fully exhausted. $35,000 will be reserved for vulnerability awards.
Submissions received after the funds have been exhausted will be handled as normal submissions within DoD’s VDP, the agency said.
“Bounties will go faster than the fireworks, and only high and critical findings will be eligible for an award. Themed bonuses are available for the best findings in different areas of the DoD,”the Department added.
The highest bug bounty rewards that are offered are of $1,000, but the DoD is promising $5,000 for the best finding of the event.
The DoD also announced that the challenge is open to the global public and that even government employees may participate, while off-duty.
Related: US DoD Launches Vuln Disclosure Program for Contractor Networks
Related: U.S. Government Announces ‘Hack the Army 3.0’ Bug Bounty Program
Related: Hackers Earn $275,000 for Vulnerabilities in U.S. Army Systems

More from Ionut Arghire
- Ransomware Will Likely Target OT Systems in EU Transport Sector: ENISA
- Ransomware Gang Publishes Data Allegedly Stolen From Maritime Firm Royal Dirkzwager
- Zoom Paid Out $3.9 Million in Bug Bounties in 2022
- Malicious NuGet Packages Used to Target .NET Developers
- Google Pixel Vulnerability Allows Recovery of Cropped Screenshots
- Millions Stolen in Hack at Cryptocurrency ATM Manufacturer General Bytes
- NBA Notifying Individuals of Data Breach at Mailing Services Provider
- Adobe Acrobat Sign Abused to Distribute Malware
Latest News
- Burnout in Cybersecurity – Can it be Prevented?
- Spain Needs More Transparency Over Pegasus: EU Lawmakers
- Ransomware Will Likely Target OT Systems in EU Transport Sector: ENISA
- Virtual Event Today: Supply Chain & Third-Party Risk Summit
- Google Suspends Chinese Shopping App Amid Security Concerns
- Verosint Launches Account Fraud Detection and Prevention Platform
- Ransomware Gang Publishes Data Allegedly Stolen From Maritime Firm Royal Dirkzwager
- Zoom Paid Out $3.9 Million in Bug Bounties in 2022
