Over 50,000 vulnerabilities have been submitted to the US Department of Defense through its vulnerability disclosure program.
The DoD Cyber Crime Center reported on March 15, 2024, that it processed its 50,000th vulnerability since introducing its crowd-sourced ethical hacking scheme in November 2016.
Unlike other bug bounty efforts, DC3's VDP is a continuous scheme welcoming ethical hackers to find vulnerabilities within US military IT systems and report them to the DoD. Its launch in November 2016 followed a successful 'Hack the Pentagon' bug bounty program running on HackerOne.
In 2018, DC3 introduced a new reporting system within VDP known as the Vulnerability Report Management Network.
It allows DC3 to automate, track, and process all reporting, creating a much more efficient process.
In 2021, DC3 and the Defense Counterintelligence and Security Agency partnered to create a 12-month pilot program dedicated to hunting bugs within the systems of small to medium organizations participating in the Defense Industrial Base.
This initiative allowed DC3 to process 1019 vulnerability reports.
The DoD has continued running standalone bug bounty programs in collaboration with HackerOne, Bugcrowd and Synack, including 'Hack the Pentagon' competition covering other departments such as the Air Force, the Marine Corps, the Army, and Defense Travel System assets.
This Cyber News was published on www.infosecurity-magazine.com. Publication date: Mon, 18 Mar 2024 15:05:05 +0000