Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

GitHub Paid Out $1.5 Million in Bug Bounties in 2022

GitHub says it paid out more than $1.5 million in bug bounties for 364 vulnerabilities in 2022, reaching a total of nearly $4 million since 2016.

Microsoft-owned code hosting platform GitHub on Tuesday announced that it paid out more than $1.57 million in rewards through its bug bounty program between February 2022 and February 2023.

As part of the program, which has been running on the HackerOne platform since 2016, GitHub handed out a total of over $3.8 million in bug bounty rewards.

Last year, the code hosting platform received more than 2,000 vulnerability reports and awarded bounties for 364 security defects. The highest number of submissions was registered in June 2022, during its H1-512 live hacking event in Austin.

A total of 45 in-person and remote researchers participated in the hacking event. Roughly half of the 182 received submissions were validated and GitHub handed out close to $700,000 in bug bounties.

“H1-512 was a fantastic opportunity for our team to experience the excitement and passion of our hackers in person. This event enabled us to break down the barriers of the screen and to make meaningful connections,” GitHub says.

The platform started a limited disclosure of reports for vulnerabilities in GitHub Enterprise Server (GHES) and open source projects that receive a CVE identifier, and plans to disclose more reports via HackerOne.

Additionally, GitHub continues to find new ways to expand its rewards for the reporting researchers, and says it will complement eligible submissions with non-monetary rewards to attract more white hat hackers to its bug bounty program.

“We encourage researchers of all levels to submit reports to our bug bounty program. Your submissions are greatly valued and impactful to ensuring the safety and security of our products, our users, and the community,” GitHub notes.

Advertisement. Scroll to continue reading.

Related: GitHub Warns of North Korean Social Engineering Attacks Targeting Tech Firm Employees

Related: GitHub Secret-Blocking Feature Now Generally Available

Related: GitHub Announces New Security Improvements

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...