Vulnerabilities

Zoom Paid Out $3.9 Million in Bug Bounties in 2022

Zoom says it paid out $3.9 million in bug bounty rewards in 2022, with a total of over $7 million awarded to researchers since 2019.

Zoom says it paid out $3.9 million in bug bounty rewards in 2022, with a total of over $7 million awarded to researchers since 2019.

Video communications giant Zoom this week announced that in 2022 it paid out $3.9 million to security researchers who reported vulnerabilities as part of its bug bounty program.

Zoom launched a private bug bounty program on HackerOne in 2019 and has paid out over $7 million in bounty rewards to date. In 2021, the company paid roughly $1.8 million in bug bounty rewards.

Moving forth, the company is working on implementing a new vulnerability impact scoring system that it will use alongside the Common Vulnerability Scoring System (CVSS) to score reports.

The new Vulnerability Impact Scoring System (VISS) will rank vulnerability reports based on 13 different aspects of their impact on Zoom’s infrastructure and technology, as well as on customer data security.

“With the implementation of VISS, Bug Bounty can focus more on measuring responsibly demonstrated impact, rather than the theoretical possibility of exploitation,” Zoom says.

What the company did not say was how many vulnerability reports it received last year and how many of these led to the release of a patch. However, Zoom issued CVE identifiers for tens of critical- and high-severity flaws across its product portfolio.

Earlier this year, Google said it paid out $12 million through its bug bounty programs in 2022. In comparison, Intel paid $935,000 in rewards last year, for a total of over $4.1 million since the beginning of its bug bounty program in 2017.

Related: QNAP Offering $20,000 Rewards via New Bug Bounty Program

Advertisement. Scroll to continue reading.

Related: Hack the Pentagon 3.0 Bug Bounty Program to Focus on Facility Control Systems

Related: Apple Paid Out $20 Million via Bug Bounty Program

Related Content

Vulnerabilities

Video conferencing giant Zoom has paid out $10 million through its bug bounty program since it was launched in 2019.

Vulnerabilities

Zoom patches seven vulnerabilities in its products, including a critical-severity bug in its Windows applications.

Vulnerabilities

Intel, AMD, Zoom and Splunk released security advisories on Patch Tuesday to inform customers about vulnerabilities found in their products.

Risk Management

Zoom launches an open source Vulnerability Impact Scoring System (VISS) tested within its bug bounty program.

Privacy

New options allow paid Zoom customers to specify certain data for meetings, webinars, and team chat to be stored within the EEA.

Vulnerabilities

Video messaging giant Zoom has released patches for multiple security vulnerabilities that expose both Windows and macOS users to malicious hacker attacks.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version