Register now for better personalized quote!

Google's new bug bounty program targets open-source vulnerabilities

Aug, 30, 2022 Hi-network.com
Image: Shutterstock

Google on Tuesday announced it's launching a new bug bounty program that focuses specifically on open-source software. Bug hunters can earn anywhere from$100 toupwards of$31,000 via the new Open Source Software Vulnerability Rewards Program (OSS VRP), depending on the severity of the vulnerability they find. 

The new program tackles a major problem in the software community -a spike in supply chain compromises. Citing a report from the software firm Sonatype, Google noted that attacks targeting the open-source supply chain grew 650% year-over-year in 2021. Even single vulnerabilities, like the severe Log4j vulnerability that was discovered in December 2021, can wreak widespread havoc. 

Google

  • Every product unveiled at the Made by Google event: Pixel 8 Pro, Watch 2, Assistant, more
  • Pixel 8 Pro vs. Pixel 7 Pro: Is it worth the upgrade?
  • Your Pixel Buds Pro are getting a major software upgrade, and it's totally free
  • How to preorder the Google Pixel 8, Pixel Watch 2, and Pixel Buds Pro now
  • ChatGPT vs. Bing Chat vs. Google Bard: Which is the best AI chatbot?

Google's new program encourages bug hunters to look for issues in up-to-date versions of open-source software (including repository settings) stored in the public repositories of Google-owned GitHub organizations (such as Google, GoogleAPIs and GoogleCloudPlatform). It also focuses on those projects' third-party dependencies. 

SEE: These are the cybersecurity threats of tomorrow that you should be thinking about today

The top awards will go to vulnerabilities found in the most sensitive projects that Google maintains, including Bazel, Angular, Golang, Protocol buffers and Fuchsia. Google also is encouraging bug hunters to look for problems that could have the greatest impact on the supply chain, which could include design issues that cause product vulnerabilities or security issues like leaked credentials.

Rewards will range from$100 to $31,337, depending on the severity of the vulnerability and the project's importance. "The larger amounts will also go to unusual or particularly interesting vulnerabilities, so creativity is encouraged," Google added in its blog post. 

The OSS VRP is part of the$10 billion that Google has committed to spending on US cybersecurity. Google made the commitment last year following a meeting at the White House, where the Biden administration stressed that potential vulnerabilities in open-source software are a national security concern.

Security

8 habits of highly secure remote workersHow to find and remove spyware from your phoneThe best VPN services: How do the top 5 compare?How to find out if you are involved in a data breach -- and what to do next
  • 8 habits of highly secure remote workers
  • How to find and remove spyware from your phone
  • The best VPN services: How do the top 5 compare?
  • How to find out if you are involved in a data breach -- and what to do next

tag-icon Hot Tags : Tech Security

Copyright © 2014-2024 Hi-Network.com | HAILIAN TECHNOLOGY CO., LIMITED | All Rights Reserved.