Monday, March 3, 2025
HomeBug BountyEU Starts Bug Bounties for 15 Free and Open Source Software Projects

EU Starts Bug Bounties for 15 Free and Open Source Software Projects

Published on

SIEM as a Service

Follow Us on Google News

Starting from January 2019, European Commission launched bug bounties program for 15 free Open Source softwares, that EU institutions rely on.

The bug bounties on open source softwares are aimed to increase in security of Free and Open Source Software.

Eu said that “We also planned a series of Hackathons that will allow software developers from within the EU institutions, and developers from Free Software projects, to work more closely together and to collaborate directly on their software.”

Bug Bounty program employs crowdsource security researchers will diverse skill set covering a wide of vulnerability scenarios and advanced threats. The BugBounty program has proved to more effective than going for traditional penetration services conducted through third-party agencies.

15 Free and Open Source Softwares

Starting form January 2019, researchers can submit bugs on Filezilla, Apache Kafka, Notepad++, PuTTY, VLC Media Player and midPoint through the leading Bug Bounty Platform HackerOne.

15 free Open Source softwares

Other 9 software projects through the Ethical Hacking platform from, the 9 projects include FLUX TL, KeePass, 7-zip, Digital Signature Services (DSS), Drupal, GNU C Library (glibc), PHP Symfony, Apache Tomcat and WSO2.

Related Read Advantages of Bug Bounty Program Over Traditional Penetration Testing

Higest bounty rewards offered to PuTTY (90.000,00 €) followed by Open source CMS Drupal (89.000,00 €).

The issue made lots of people realise how important Free and Open Source Software is for the integrity and reliability of the Internet and other infrastructure, reads the blog post published by European Parliament member.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Hackers Using PowerShell and Microsoft Legitimate Apps to Deploy Malware

Cybersecurity experts are warning of an increasing trend in fileless attacks, where hackers leverage...

JavaGhost: Exploiting Amazon IAM Permissions for Phishing Attacks

Unit 42 researchers have observed a threat actor group known as JavaGhost exploiting misconfigurations...

New Poco RAT Via Weaponized PDF Attacking Users to Capture Sensitive Data

A new variant of malware, dubbed "Poco RAT," has emerged as a potent espionage...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Hackers Using PowerShell and Microsoft Legitimate Apps to Deploy Malware

Cybersecurity experts are warning of an increasing trend in fileless attacks, where hackers leverage...

JavaGhost: Exploiting Amazon IAM Permissions for Phishing Attacks

Unit 42 researchers have observed a threat actor group known as JavaGhost exploiting misconfigurations...