Skip to main content

Woburn, MA – March 6, 2018 – As part of its Global Transparency Initiative, Kaspersky Lab is extending its successful bug bounty program to include rewards of up to $100,000 for the discovery and coordinated disclosure of severe vulnerabilities in some of its leading products. The opportunity to get this bounty is available to all members of the HackerOne platform, Kaspersky Lab’s partner for the bug bounty initiative. This is a 20-fold increase on existing rewards, and is evidence of the company’s commitment to ensuring the complete integrity of its products and protection for customers.

The top reward is available for the discovery of bugs that enable remote code execution via the product database update channel, with the launch of malware code taking place silently from the user in the product’s high privilege process and being able to survive the reboot of the system. Vulnerabilities allowing other types of remote code execution will be awarded bounties ranging from $5,000 to $20,000 (depending on the level of complexity of a given vulnerability). Bugs allowing local privilege escalation or leading to sensitive data disclosure will also be awarded bounty payouts.   

Rewards are available for the discovery of previously unknown vulnerabilities in the following products: Kaspersky Internet Security 2019 (the most recent beta) and Kaspersky Endpoint Security 11 (the most recent beta), running on Desktop Windows version 8.1 or higher, with the most recent updates installed. 

Further details of requirements and eligibility are available here.

“Finding and fixing bugs is a priority for us as a software company. We invite security researchers to make sure there are no vulnerabilities in our products,” said Eugene Kaspersky, CEO of Kaspersky Lab. “The immunity of our code and highest levels of protection that we offer customers is a core principal of our business – and a fundamental pillar of our Global Transparency Initiative.”

Launched in 2016, the company’s bug bounty program encourages independent security researchers to supplement the company’s own work in vulnerability detection and mitigation. The program has already led to more than 70 bug reports related to Kaspersky Lab products and services being resolved, thus making them even more secure.

The company’s Global Transparency Initiative, announced on October 23, 2017, is designed to engage the broader information security community and other stakeholders in validating and verifying Kaspersky Lab’s products, internal processes and business operations, as well as introducing additional accountability mechanisms by which the company can further demonstrate that it addresses any security issues promptly and thoroughly.

About Kaspersky Lab

Kaspersky Lab is a global cybersecurity company, which has been operating in the market for over 20 years. Kaspersky Lab’s deep threat intelligence and security expertise is constantly transforming into next generation security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky Lab technologies and we help 270,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Media Contact
Jessica Bettencourt
774.451.5142
Jessica.Bettencourt@kaspersky.com

Kaspersky Lab boosts bug bounty program with reward of $100,000 as part of its Global Transparency Initiative

As part of its Global Transparency Initiative, Kaspersky Lab is extending its successful bug bounty program to include rewards of up to $100,000 for the discovery and coordinated disclosure of severe vulnerabilities in some of its leading products.
Kaspersky Logo