Why 2022 was a record-breaking year in bug bounty awards
Blog post from GitLab
In 2022, GitLab's Application Security team celebrated a record-breaking year for its bug bounty program, awarding over $1 million in bounties across 221 valid reports, significantly up from the previous year. This surge in activity was attributed to increased engagement from researchers and an enhanced bounty award structure. The team received 920 reports from 424 researchers, resolving 158 valid reports and publicly sharing 94. Notable achievements included high earnings by researchers, exceptional reports on remote code execution, and innovative findings like a novel local git read vulnerability. GitLab also introduced new initiatives such as a $20,000 capture the flag bonus and resources like "Reproducible Vulnerabilities" to aid learning. The organization emphasized transparency in their processes and continued to provide educational content through various platforms, reinforcing its commitment to leading in industry standards for bug bounty programs.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.