Sunday, April 6, 2025
HomeBug BountyHackerOne Removed Kaspersky Bug Bounty Program From Its Platform

HackerOne Removed Kaspersky Bug Bounty Program From Its Platform

Published on

SIEM as a Service

Follow Us on Google News

HackerOne is one of the biggest bug bounty platforms for all security researchers and companies. Lots of bugs have been discovered by individual researchers at HackerOne which prevented several security misconfigurations.

Yesterday, Kaspersky announced on Twitter that HackerOne has removed its bug bounty program from its platform. They also claimed that

HackerOne never gave any announcement before removing their program. They have removed Kaspersky’s access to their platform and made their bug bounty program page unavailable to researchers.

- Advertisement - Google News

Kaspersky stated that “Kaspersky finds this unilateral action an unacceptable behavior, especially for the key player in the vulnerability coordination community where the trust between all parties is paramount to making products and services safer. This is detrimental to the vital issue of global cybersecurity

Kaspersky has also mentioned several questions about their bounty program like,

  • What happens to vulnerabilities already reported?
  • Who possesses this information now?
  • What was communicated to participating researchers? 
  • What happens with the money that was deposited with HackerOne?

Why does the company fail to communicate its policies and next steps to all partners and the wider security community with enough lead time to settle any existing issues?

However, HackerOne had an FAQ about their sanctions-related suspensions which stated that

“We will continue to work with the appropriate entities on sanctions. To that end, we have suspended programs for customers based in the countries of Russia, Belarus, and the sanctioned areas of Ukraine. However, HackerOne will NOT block access to any vulnerability disclosures submitted prior to suspension of services” which Kaspersky says doesn’t qualify as an acceptable answer.

Kaspersky also mentioned security researchers to continue on reporting vulnerabilities which they stated on their support page or email them.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hack The box “Ghost” Challenge Cracked – A Detailed Technical Exploit

Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a...

Sec-Gemini v1 – Google’s New AI Model for Cybersecurity Threat Intelligence

Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by...

U.S. Secures Extradition of Rydox Cybercrime Marketplace Admins from Kosovo in Major International Operation

The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir...

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Hack The box “Ghost” Challenge Cracked – A Detailed Technical Exploit

Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a...

Sec-Gemini v1 – Google’s New AI Model for Cybersecurity Threat Intelligence

Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by...

U.S. Secures Extradition of Rydox Cybercrime Marketplace Admins from Kosovo in Major International Operation

The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir...