Video communications giant Zoom this week announced that in 2022 it paid out $3.9 million to security researchers who reported vulnerabilities as part of its bug bounty program.
Zoom launched a private bug bounty program on HackerOne in 2019 and has paid out over $7 million in bounty rewards to date. In 2021, the company paid roughly $1.8 million in bug bounty rewards.
Moving forth, the company is working on implementing a new vulnerability impact scoring system that it will use alongside the Common Vulnerability Scoring System (CVSS) to score reports.
The new Vulnerability Impact Scoring System (VISS) will rank vulnerability reports based on 13 different aspects of their impact on Zoom’s infrastructure and technology, as well as on customer data security.
“With the implementation of VISS, Bug Bounty can focus more on measuring responsibly demonstrated impact, rather than the theoretical possibility of exploitation,” Zoom says.
What the company did not say was how many vulnerability reports it received last year and how many of these led to the release of a patch. However, Zoom issued CVE identifiers for tens of critical- and high-severity flaws across its product portfolio.
Earlier this year, Google said it paid out $12 million through its bug bounty programs in 2022. In comparison, Intel paid $935,000 in rewards last year, for a total of over $4.1 million since the beginning of its bug bounty program in 2017.
Related: QNAP Offering $20,000 Rewards via New Bug Bounty Program
Related: Hack the Pentagon 3.0 Bug Bounty Program to Focus on Facility Control Systems
Related: Apple Paid Out $20 Million via Bug Bounty Program

More from Ionut Arghire
- Blackpoint Raises $190 Million to Help MSPs Combat Cyber Threats
- ‘Asylum Ambuscade’ Group Hit Thousands in Cybercrime, Espionage Campaigns
- Google Cloud Now Offering $1 Million Cryptomining Protection
- Pharmaceutical Giant Eisai Takes Systems Offline Following Ransomware Attack
- North Korean Hackers Blamed for $35 Million Atomic Wallet Crypto Theft
- Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions
- Android’s June 2023 Security Update Patches Exploited Arm GPU Vulnerability
- US, Israel Provide Guidance on Securing Remote Access Software
Latest News
- In Other News: AI Regulation, Layoffs, US Aerospace Attacks, Post-Quantum Encryption
- Blackpoint Raises $190 Million to Help MSPs Combat Cyber Threats
- Google Introduces SAIF, a Framework for Secure AI Development and Use
- ‘Asylum Ambuscade’ Group Hit Thousands in Cybercrime, Espionage Campaigns
- Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021
- SaaS Ransomware Attack Hit Sharepoint Online Without Using a Compromised Endpoint
- Google Cloud Now Offering $1 Million Cryptomining Protection
- Democrats and Republicans Are Skeptical of US Spying Practices, an AP-NORC Poll Finds
