VK Bug Bounty Director Petr Uvarov told a ComNews correspondent that VK has one of the oldest Bug Bounty programs on the Russian market: "VK has presented more than 30 programs on all three Russian Bug Bounty platforms - Standoff Bug Bounty, BI.Zone Bug Bounty, bugbounty.ru. This was done specifically to cover as many bug hunters as possible. In 2023, the total reward on all three platforms exceeded 39 million rubles, which is three times more than in 2022, and the maximum one-time payment was 2.4 million rubles. In 2024, we launched the Bounty pass mechanics and increased the cost of maximum rewards in a number of programs, which will obviously affect the final amount of payments at the end of the year."
told a ComNews correspondent singapore whatsapp number database that payments in the Wildberries Bug Bounty program correspond to the market average: "We are adding all our new services and products to the Bug Bounty program. Also last month, domains related to warehouse infrastructure were added. Over the first half of 2024, more than 1 million rubles were paid out, and the number of products in which vulnerabilities were identified was about 20. At the same time, in the second half of 2024, we significantly increased the amount of payments, and now the maximum reward is half a million rubles. Over the entire period of the Bug Bounty program in Wildberries, the company's services have been checked by more than 100 specialists, who have been paid more than 5 million rubles."
Head of Software Security Department at Kaspersky Lab Dmitry Shmoylov said that the company implements a multi-level approach to product testing, which is part of the secure software development life cycle: "Before entering the market, any solution undergoes a thorough internal audit, analysis by a team of professional testers from the quality assurance (QA) department, as well as penetration tests by a team of internal pentesters. At the same time, in order to reduce the likelihood of detecting vulnerabilities and their malicious use to almost zero, in 2016 Kaspersky Lab launched the Bug Bounty program, which is implemented as part of the Global Transparency Initiative (GTI). We work with the French platform Yogosha (from 2023 to 2024, payments amounted to 13 thousand euros). From 2016-2022, we worked with the main Bug Bounty platform - HackerOne (payments amounted to $80 thousand). At the same time, the maximum reward in the Bug Bounty program - up to $100 thousand for detecting the most serious vulnerabilities in Kaspersky Lab software - has not yet been awarded to anyone."
A representative of the press service of Wildberries LLC
-
- Posts: 470
- Joined: Thu Jan 02, 2025 7:24 am