Vulnerabilities / Threats

4/17/2017
01:35 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Kaspersky Lab Extends Bug Bounty Program

Woburn, MA – April 14, 2017 - Kaspersky Lab announced the extension of its bug bounty program, with leading bug bounty platform provider HackerOne, to continue encouraging qualified individuals and organizations to submit reports on vulnerabilities found in the company’s products.

Launched in August 2016, the initial phase of the program helped to successfully uncover roughly 20 bugs in its first six months. As a result, the program is being extended. Initially, researchers were asked to examine Kaspersky Lab’s flagship products for consumers and enterprises, Kaspersky Internet Security 2017 and Kaspersky Endpoint Security 10. Now the company is also adding Kaspersky Password Manager 8, and as an additional incentive for researchers, Kaspersky Lab increased the rewards for remote code execution bugs from $2,000 to $5,000.

With today’s increasingly complex security landscape, bug bounty programs are an effective way for security companies to incentivize external researchers to safely find and disclose software vulnerabilities. In addition to other internal measures, bug bounty programs help companies continuously improve their security tools and provide multiple layers of protection for customers.

“The security of our customers is our priority. That is why we take independent research into our products very seriously and apply its results to constantly improve our best-in-class technologies,” said Nikita Shvetsov, chief technology officer at Kaspersky Lab. “Since August, it is fair to say that our Bug Bounty Program has been successful in optimizing our internal and external mitigation measures to continuously improve the resiliency of our products, which is why we’ve decided to extend it. We also appreciate the enthusiastic participation of security researchers worldwide. As a mark of our respect for the work they do in helping us to bolster our solutions, we’ve increased the remuneration on offer in this second phase of the program and extended the scope to include other important Kaspersky Lab products.”

“Kaspersky Lab is a great example of an organization that prioritizes security at every level,” said Alex Rice, co-founder and CTO at HackerOne. “They recognize the responsibility they have to protect customers — both enterprises and consumers — and are taking every step to ensure vulnerabilities are found and fixed before they can be exploited. The expansion of their program shows their commitment to investing in the global hacker community and ensuring their competitive edge in the security market.”

For more information on the Kaspersky Lab Bug Bounty Program, including eligibility, rewards, exceptions and rules, please visit: https://hackerone.com/kaspersky

About Kaspersky Lab

Kaspersky Lab is a global cybersecurity company founded in 1997. Kaspersky Lab’s deep threat intelligence and security expertise is constantly transforming into security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky Lab technologies and we help 270,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

About HackerOne
HackerOne is the no.1 hacker-powered security provider, connecting organizations with the world’s largest community of trusted hackers. More than 800 organizations, including The U.S. Department of Defense, General Motors, Intel, Uber, Twitter, GitHub, Nintendo, Kaspersky Lab, Lufthansa, Panasonic Avionics, Qualcomm, Square, Starbucks, Dropbox and the CERT Coordination Center trust HackerOne to find critical software vulnerabilities before criminals can exploit them. HackerOne customers have resolved more than 43,000 vulnerabilities and awarded more than $15M in bug bounties. HackerOne is headquartered in San Francisco with offices in London, Seattle, Los Angeles and the Netherlands. For more information, please visit https://hackerone.com.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: In Russia, application hangs YOU!
Current Issue
Flash Poll
How Data Breaches Affect the Enterprise
How Data Breaches Affect the Enterprise
This report, offers new data on the frequency of data breaches, the losses they cause, and the steps that organizations are taking to prevent them in the future. Read the report today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-3912
PUBLISHED: 2018-09-18
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
CVE-2018-6690
PUBLISHED: 2018-09-18
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.
CVE-2018-6693
PUBLISHED: 2018-09-18
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escal...
CVE-2018-16515
PUBLISHED: 2018-09-18
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
CVE-2018-16794
PUBLISHED: 2018-09-18
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.