Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Cyber Attacks
  • The DHS is inviting hackers to break into its systems, but there are rules of engagement
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

The DHS is inviting hackers to break into its systems, but there are rules of engagement

4 years ago Graham Cluley
The DHS is inviting hackers to break into its systems, but there are rules of engagement

The United States Department of Homeland Security (DHS) is inviting security researchers to uncover vulnerabilities and hack into its systems, in an attempt to better protect itself from malicious attack.

The DHS says that it is launching the “Hack DHS” bug bounty program to “identify potential cybersecurity vulnerabilities within certain DHS systems and increase the Department’s cybersecurity resilience.”

According to the DHS, whose Alejandro Mayorkas announced the initiative at the Bloomberg Technology Summit, “Hack DHS” will have three phases:

  1. Hackers will conduct virtual assessments on certain DHS external systems.
  2. Hackers will participate in a live, in-person hacking event.
  3. DHS will identify and review lessons learned, and plan for future bug bounties.

DHS Secretary Mayorkas said that between $500 and $5000 would be paid for each vulnerability uncovered, depending on the severity of the bug discovered. In order to be eligible for a reward, security researchers will have to disclose full details of the flaw with the DHS, including how it can be exploited, and how it could be used by a malicious hacker to steal information.

Of course, bug bounties are nothing new. Many private sector companies operate bug bounty programs to encourage responsible disclosure of vulnerabilities, and in recent years the likes of the US Army and Pentagon have offered financial rewards for pre-approved security researchers to participate in bug hunts.

And rather than reinvent the wheel, “Hack DHS” appears to be building on the foundations of such initiatives, ensuring that strong guidelines are put in place to prevent chaos ensuing.

Therefore, I would expect “Hack DHS” to follow in the footsteps of the “Hack the Pentagon” bug bounty which imposed the following rules:

  • You must have pre-registered and been approved to take part in the program.
  • You must be eligible to work in the United States.
  • You can’t be residing in a country currently under US trade sanctions. So, Syrian and North Korean hackers are not welcome!
  • You can’t be on the US Department of Treasury’s list of bad guys and organisations who have engaged in terrorism, drug trafficking and other crimes.
  • Every participant has to agree to undergo a background check.

In addition, the DHS will be putting tight parameters in place around what systems are within scope for the bug bounty, and about what types of vulnerabilities it is interested in receiving reports.

In the greater scheme of things, a maximum $5000 bounty is not tremendously generous, especially when companies to other bug-finding initiatives – but one imagines that some security researchers will appreciate the kudos they could receive for helping the DHS stamp out potentially highly-critical security holes in its systems.


Editor’s Note: The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

The post ” The DHS is inviting hackers to break into its systems, but there are rules of engagement” appeared first on TripWire

Source:TripWire – Graham Cluley

Tags: Bug, Critical Severity, Goverment, Hacker, TripWire

Continue Reading

Previous New Fileless Malware Uses Windows Registry as Storage to Evade Detection
Next The Guide to Automating Security Training for Lean Security Teams

More Stories

  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

China-Linked UNC3886 Targets Singapore Telecom Sector in Cyber Espionage Campaign

3 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers

5 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

⚡ Weekly Recap: AI Skill Malware, 31Tbps DDoS, Notepad++ Hack, LLM Backdoors and More

7 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

How Top CISOs Solve Burnout and Speed up MTTR without Extra Hiring

9 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign

9 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

TeamPCP Worm Exploits Cloud Infrastructure to Build Criminal Infrastructure

11 hours ago [email protected] (The Hacker News)

Recent Posts

  • China-Linked UNC3886 Targets Singapore Telecom Sector in Cyber Espionage Campaign
  • SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers
  • ⚡ Weekly Recap: AI Skill Malware, 31Tbps DDoS, Notepad++ Hack, LLM Backdoors and More
  • How Top CISOs Solve Burnout and Speed up MTTR without Extra Hiring
  • Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT