The US Department of Defense (DoD) has launched a new website to help organizations within the department to launch bug bounty programs and recruit security researchers. The new Hack the Pentagon (HtP) website, launched by the Chief Digital and Artificial Intelligence Office (CDAO) Directorate for Digital Services (DDS), is meant as a companion for the DoD’s long-running bug bounty program with the same name.
Initially launched in 2016, the DoD’s bug bounty program has resulted in more than 1,600 white hat hackers reporting over 2,100 vulnerabilities in Pentagon systems and assets and earning over $650,000 in bounty payments. Vetted security researchers have identified issues in networks, in planes, next-generation secure hardware, power and HVAC systems, water facilities, and more.
The DoD’s HtP website will serve as a platform to provide organizations within the department with access to lessons learned and best practices for conducting bug bounty programs. It will also allow DoD organizations to recruit security researchers to participate in their bug bounty programs. To date, the DoD has run more than 40 bug bounty projects, including Hack the Pentagon, Hack the Air Force, Hack the Army, Hack the Marine Corps, Hack the Defense Travel System, Hack DHS, and Hack US.
The DoD’s bug bounty program has been a success so far, and the launch of the HtP website is an exciting next step in the department’s commitment to cybersecurity. By providing organizations with the resources to run successful bug bounty programs and access to security researchers, the DoD is better equipped to protect its systems and assets from malicious actors.
Key Points:
- The US Department of Defense (DoD) has launched a new website, Hack the Pentagon (HtP), to help organizations within the department to launch bug bounty programs and recruit security researchers.
- The DoD’s bug bounty program has been running since 2016, and has resulted in over 2,100 vulnerabilities reported and more than $650,000 in bounty payments.
- The DoD’s HtP website will provide organizations with access to lessons learned and best practices for conducting bug bounty programs, as well as access to security researchers for their programs.
- To date, the DoD has run more than 40 bug bounty projects.
- The launch of the HtP website is an exciting next step in the department’s commitment to cybersecurity.