subscribe: Daily Newsletter


Kaspersky puts a price on bugs’ heads


At the Black Hat USA conference this week, Kaspersky Lab launched the Kaspersky Lab Bug Bounty Program with HackerOne, a leading bug bounty platform provider.
With this programme, Kaspersky Lab will not only further bolster its mitigation strategy for addressing inherent software vulnerabilities, but also continue enhancing its relationship with external security researchers.
Today’s cyber threat landscape is becoming increasingly complex, requiring security companies to continuously identify and implement effective tools in order to provide the most robust level of protection. Bug bounty programs are an effective and proven security measure that incentivises external researchers to safely find and disclose software vulnerabilities to companies. As a result, these organisations are able to fix the reported issues without placing customers at risk.
The first phase of the Kaspersky Lab bug bounty program officially began on 2 August 2016 and last for a six-month period. During this initial phase, Kaspersky Lab will offer a total of $50 000 in bounty rewards to security researchers.
Bug bounty participants will examine our flagship products for consumers and enterprises, Kaspersky Internet Security and Kaspersky Endpoint Security.
After the preliminary phase is complete, the company will evaluate the results to determine what additional products and rewards should be included in the second phase of its bounty programme.
“Our bug bounty programme will help amplify the current internal and external mitigation measures we use to continuously improve the resiliency of our products,” says Nikita Shvetsov, chief technology officer at Kaspersky Lab. “We think it’s time for all security companies, large and small, to work more closely with external security researchers by embracing bug bounty programs as an effective and necessary tool to help keep their products secure and their customers protected.”
“Vulnerabilities are inevitable and bug bounty programmes are proven to supplement traditional security best practices with the help of the incredibly diverse global hacker community,” says Alex Rice, chief technology officer and co-founder of HackerOne. “We look forward to partnering with Kaspersky Lab to help them run the most competitive bug bounty programme and continue to protect customers.”