AT&T HackerOne bug bounty program | xxxAT&T HackerOne bug bounty program – xxx
菜单

AT&T HackerOne bug bounty program

八月 6, 2019 - BleepingComputer

AT&T HackerOne bug bounty program

Today AT&T is announcing their launch of a new public bug bounty programs on the HackerOne platform. This program will allow security researchers to report security bugs to AT&T in order receive a monetary reward.

Many people associate AT&T as being solely a communications company, when in fact they also own media companies such as WarnerMedia, WarnerMedia Entertainment,  AT&T Latin America, and Xander.  This bug bounty program will now encompass all of “AT&T’s public-facing online environment, including all AT&T-owned websites, public APIs, mobile applications, and devices for potential vulnerabilities and securely disclose them to AT&T”.

This is not the first bug bounty program run by AT&T. Previously they were running a bounty program through their AT&T Developer API Platform.

This program, though, only paid the top 25 researchers on a quarterly basis based on the impact of the reported bugs. With researchers having to meet a certain threshold to earn a bug bounty award and only if their bugs had a certain level of criticality, there was little to incentivize researchers to focus on AT&T bugs.

By transitioning to a HackerOne platform where researchers are paid for every vulnerability that is resolved, they hope to harness the power of a larger community while triaging reports through HackerOne.

AT&T HackerOne bug bounty program

The AT&T bug bounty program was launched privately in July by inviting 100-150 researchers that they worked with in the past on their AT&T Developer API Platform.

Since then the program has received 49 submitted bug reports with a total of $8,150 bug bounties paid. The average bounty paid is currently at $150, with their highest being $750.

Under this program the payouts for reported bugs are:

AT&T has not shared what types of bugs fit into each classification and have stated that “the criteria used to determine the payout for a vulnerability is solely at the discretion of AT&T.”

HackerOne told BleepingComputer that this “is the first communications company of this size to launch a public bug bounty program of this scale with HackerOne.”

Related Articles:

Cracked Tesla 3 Windshield Leads to $10,000 Bug Bounty

VLC 3.0.7 is Biggest Security Release Due to EU Bounty Program

Forum Rules and Posting Guidelines

Bleeping Computer® is a community of individuals of all ages who are here to learn new information, to help each other, and to help their fellow peers. With that in mind, we ask that all members please follow these simple rules in order to create an atmosphere where everyone feels comfortable.

The rules are as follows:

Violation of any of these rules can lead to a banning of the user from our Web Site and a deletion of their account. The consequences will be determined by the Staff on a case by case basis.

When posting you agree that the administrators and the moderators of this forum have the right to modify, delete, edit or close any topic, signature, account, or profile data at any time that they see fit. If you have any questions concerning this, please do not start a new thread, but rather private message to an administrator or moderator.

contact us


Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51