HackerOne is one of the biggest bug bounty platforms for all security researchers and companies. Lots of bugs have been discovered by individual researchers at HackerOne which prevented several security misconfigurations.
Yesterday, Kaspersky announced on Twitter that HackerOne has removed its bug bounty program from its platform. They also claimed that
HackerOne never gave any announcement before removing their program. They have removed Kaspersky’s access to their platform and made their bug bounty program page unavailable to researchers.
Kaspersky stated that “Kaspersky finds this unilateral action an unacceptable behavior, especially for the key player in the vulnerability coordination community where the trust between all parties is paramount to making products and services safer. This is detrimental to the vital issue of global cybersecurity”
Kaspersky has also mentioned several questions about their bounty program like,
Why does the company fail to communicate its policies and next steps to all partners and the wider security community with enough lead time to settle any existing issues?
However, HackerOne had an FAQ about their sanctions-related suspensions which stated that
“We will continue to work with the appropriate entities on sanctions. To that end, we have suspended programs for customers based in the countries of Russia, Belarus, and the sanctioned areas of Ukraine. However, HackerOne will NOT block access to any vulnerability disclosures submitted prior to suspension of services” which Kaspersky says doesn’t qualify as an acceptable answer.
Kaspersky also mentioned security researchers to continue on reporting vulnerabilities which they stated on their support page or email them.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a disguised…
Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated attack…
The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms in…
A critical vulnerability, CVE-2024-3393, has been identified in the DNS Security feature of Palo Alto…
Threat Analysts have reported alarming findings about the "Araneida Scanner," a malicious tool allegedly based…
A major dark web operation dedicated to circumventing KYC (Know Your Customer) procedures, which involves…