Bug bounty programs focus on Russia – with potential far-reaching implications

A number of Russian government agencies have partnered with Standoff 365 and BI.ZONE, reflecting a shift in the bug bounty program and the Russian hacking community, which until recently was seen as a security threat rather than a means of self-improvement. .

In February 2023, the Ministry of Digital Development registered 10 of its government e-systems, including Gosuslugi, the state services portal of the Russian Federation, in both the Standoff 365 Bug Bounty and the Bi.ZONE Bug Bounty platform. The maximum payout for a significant risk is ₽1 million (US$11,000). According to the Ministry, more than 16,000 people have signed up for the government’s anti-bug program, as more than 100 vulnerabilities have been identified so far.

These federal efforts also trickle down to state governments. In December 2023, the municipal services of the Moscow Region (uslugi.mosreg.ru) launched its own bug bounty program in Standoff 365, followed by Rostov Oblast in the same month with its geographic information system (RO GIS), and the Republic. of Sakha also opened its electronic services for bug hunting in May 2024. Unlike programs started by private companies, those linked to government agencies are open only to citizens of the Russian Federation.


Source link