Bug bounty programs are dominated by large enterprises, leaving small and mid-sized businesses (SMBs) and managed service providers (MSPs) underserved despite facing the same cyber threats. Supply chain attacks like SolarWinds, Kaseya, and Log4Shell have exposed how vulnerable the MSP ecosystem is. Security researchers gravitate toward high-paying programs, ignoring smaller vendors. Huntress and partners have funded the Dutch Institute for Vulnerability Disclosure (DIVD) to run a bug bounty program specifically targeting MSP software, aiming to attract researcher attention to this underserved segment and level the security playing field.

7m read timeFrom huntress.com
Post cover image
Table of contents
The State of Affairs for Security ResearchersOpen-Source Software: An Attractive Target for HackersBug Bounty ProgramsSo Where Does That Leave the 99%?Learn More
1 Impression