Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Bug Bounty Programs Paying Off for Vendors, Security Researchers

    By
    Sean Michael Kerner
    -
    August 4, 2015

    eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

    PrevNext

    1Bug Bounty Programs Paying Off for Vendors, Security Researchers

    1 - Bug Bounty Programs Paying Off for Vendors, Security Researchers

    More companies are finding bug bounty programs to be an effective method of improving security. And Bugcrowd’s recent bug bounty report bears that out.

    2Private Bug Bounty Programs Growing Fast

    2 - Private Bug Bounty Programs Growing Fast

    Bugcrowd operates both public and invitation-only private bug bounty programs. Over the last 30 months, Bugcrowd has found a 36.1 percent submission success rate with invitation-only programs, in contrast to an 18 percent valid bug submission rate for public programs.

    3India Is the Top Bug Submission Country

    3 - India Is the Top Bug Submission Country

    India is the top source for bug report submissions, followed by the United States and the United Kingdom.

    4XSS Is the Top Vulnerability Type

    4 - XSS Is the Top Vulnerability Type

    Bugcrowd’s community submitted multiple types of vulnerabilities, with cross-site scripting (XSS) topping the list at 17.9 percent. However, Bugcrowd identifies a whopping 67.7 percent of bug types as “other.”

    5Information Leakage Bugs Often Submitted

    5 - Information Leakage Bugs Often Submitted

    Looking into the 67.7 percent of vulnerability types that Bugcrowd has classified as “other,” information leakage is identified as one of the most submitted types of flaws.

    6Average Payment per Bug Is $200

    6 - Average Payment per Bug Is $200

    While bug payments vary, the average reward reported by Bugcrowd in 2015 now stands at $200, which is a marginal increase from the $180 average in 2013.

    7Top Payment Was $10,000

    7 - Top Payment Was $10,000

    While the average bug payout is $200, the top bug reward reported by Bugcrowd was a $10,000 award paid out in the second quarter of 2014. The big payout was made for a cross-site request forgery (CSRF) vulnerability.

    8Total Bug Bounty Payout to Date: $724,014.02

    8 - Total Bug Bounty Payout to Date: $724,014.02

    For the 30-month period that the report covered, Bugcrowd’s clients paid out a total of $724,014.02 to 566 different researchers.

    PrevNext

    Get the Free Newsletter!

    Subscribe to Daily Tech Insider for top news, trends & analysis

    MOST POPULAR ARTICLES

    Artificial Intelligence

    9 Best AI 3D Generators You Need...

    Sam Rinko - June 25, 2024 0
    AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
    Read more
    Cloud

    RingCentral Expands Its Collaboration Platform

    Zeus Kerravala - November 22, 2023 0
    RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
    Read more
    Artificial Intelligence

    8 Best AI Data Analytics Software &...

    Aminu Abdullahi - January 18, 2024 0
    Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
    Read more
    Latest News

    Zeus Kerravala on Networking: Multicloud, 5G, and...

    James Maguire - December 16, 2022 0
    I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
    Read more
    Video

    Datadog President Amit Agarwal on Trends in...

    James Maguire - November 11, 2022 0
    I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
    Read more
    Logo

    eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

    Facebook
    Linkedin
    RSS
    Twitter
    Youtube

    Advertisers

    Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

    Advertise with Us

    Menu

    • About eWeek
    • Subscribe to our Newsletter
    • Latest News

    Our Brands

    • Privacy Policy
    • Terms
    • About
    • Contact
    • Advertise
    • Sitemap
    • California – Do Not Sell My Information

    Property of TechnologyAdvice.
    © 2024 TechnologyAdvice. All Rights Reserved

    Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.