{"id":8999,"date":"2024-08-31T03:16:12","date_gmt":"2024-08-30T21:46:12","guid":{"rendered":"https:\/\/www.satup.xyz\/index.php\/2024\/08\/31\/adobe-transforms-public-vulnerability-disclosure-program-into-a-paid-bug-bounty-program-by-renae-kang-jul-2024\/"},"modified":"2024-08-31T03:16:12","modified_gmt":"2024-08-30T21:46:12","slug":"adobe-transforms-public-vulnerability-disclosure-program-into-a-paid-bug-bounty-program-by-renae-kang-jul-2024","status":"publish","type":"post","link":"https:\/\/www.satup.xyz\/index.php\/2024\/08\/31\/adobe-transforms-public-vulnerability-disclosure-program-into-a-paid-bug-bounty-program-by-renae-kang-jul-2024\/","title":{"rendered":"Adobe Transforms Public Vulnerability Disclosure Program into a Paid Bug Bounty Program | by Renae Kang | Jul, 2024"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<div>\n<h2 id=\"45b2\" class=\"pw-subtitle-paragraph hr gt gu bf b hs ht hu hv hw hx hy hz ia ib ic id ie if ig cq du\">By <a class=\"af ih\" href=\"https:\/\/www.linkedin.com\/in\/venturadaniel42\/\" rel=\"noopener ugc nofollow\" target=\"_blank\">Daniel Ventura<\/a>, Manager of Product Security Incident Response Team (PSIRT)<\/h2>\n<div>\n<div class=\"speechify-ignore ab cp\">\n<div class=\"speechify-ignore bh l\">\n<div class=\"ii ij ik il im ab\">\n<div>\n<div class=\"ab in\"><a href=\"https:\/\/medium.com\/@renaekang97?source=post_page-----a1f199f8e29e--------------------------------\" rel=\"noopener follow\"><\/p>\n<div>\n<div class=\"bm\" aria-hidden=\"false\">\n<div class=\"l io ip by iq ir\">\n<div class=\"l fj\"><img loading=\"lazy\" decoding=\"async\" alt=\"Renae Kang\" class=\"l fd by dd de cx\" src=\"https:\/\/miro.medium.com\/v2\/resize:fill:88:88\/1*_2c2rNBYDHH7262294wRcA.jpeg\" width=\"44\" height=\"44\" loading=\"lazy\" data-testid=\"authorPhoto\"\/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/a><a href=\"https:\/\/blog.developer.adobe.com\/?source=post_page-----a1f199f8e29e--------------------------------\" rel=\"noopener  ugc nofollow\"><\/p>\n<div class=\"iu ab fj\">\n<div>\n<div class=\"bm\" aria-hidden=\"false\">\n<div class=\"l iv iw by iq ix\">\n<div class=\"l fj\"><img loading=\"lazy\" decoding=\"async\" alt=\"Adobe Tech Blog\" class=\"l fd by br iy cx\" src=\"https:\/\/miro.medium.com\/v2\/resize:fill:48:48\/1*riyFijvwTfGcWNf1guRNtg.png\" width=\"24\" height=\"24\" loading=\"lazy\" data-testid=\"publicationPhoto\"\/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<figure class=\"nm nn no np nq nr nj nk paragraph-image\">\n<div role=\"button\" tabindex=\"0\" class=\"ns nt fj nu bh nv\">\n<div class=\"nj nk nl\"><picture><source srcset=\"https:\/\/miro.medium.com\/v2\/resize:fit:640\/format:webp\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 640w, https:\/\/miro.medium.com\/v2\/resize:fit:720\/format:webp\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 720w, https:\/\/miro.medium.com\/v2\/resize:fit:750\/format:webp\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 750w, https:\/\/miro.medium.com\/v2\/resize:fit:786\/format:webp\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 786w, https:\/\/miro.medium.com\/v2\/resize:fit:828\/format:webp\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 828w, https:\/\/miro.medium.com\/v2\/resize:fit:1100\/format:webp\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 1100w, https:\/\/miro.medium.com\/v2\/resize:fit:1400\/format:webp\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 1400w\" sizes=\"(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px\" type=\"image\/webp\"\/><source data-testid=\"og\" srcset=\"https:\/\/miro.medium.com\/v2\/resize:fit:640\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 640w, https:\/\/miro.medium.com\/v2\/resize:fit:720\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 720w, https:\/\/miro.medium.com\/v2\/resize:fit:750\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 750w, https:\/\/miro.medium.com\/v2\/resize:fit:786\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 786w, https:\/\/miro.medium.com\/v2\/resize:fit:828\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 828w, https:\/\/miro.medium.com\/v2\/resize:fit:1100\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 1100w, https:\/\/miro.medium.com\/v2\/resize:fit:1400\/1*LuOSRFZF0xXQZrftmk_T5w.jpeg 1400w\" sizes=\"(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px\"\/><img fetchpriority=\"high\" alt=\"\" class=\"bh mq nw c\" width=\"700\" height=\"400\" loading=\"eager\" role=\"presentation\"\/><\/picture><\/div>\n<\/div><figcaption class=\"nx ff ny nj nk nz oa bf b bg z du\">Generated with <a class=\"af ih\" href=\"https:\/\/www.adobe.com\/products\/firefly.html\" rel=\"noopener ugc nofollow\" target=\"_blank\">Adobe Firefly<\/a>.<\/figcaption><\/figure>\n<p id=\"4079\" class=\"pw-post-body-paragraph ob oc gu od b hs oe of og hv oh oi oj ok ol om on oo op oq or os ot ou ov ow gn bk\">As Adobe\u2019s bug bounty programs continue to evolve, we seek to collaborate with more security researchers across the globe to help make a positive impact on securing the digital world at scale. Adobe offers two (2) bug bounty programs: a private bug bounty program, where proven hackers are offered exclusive access and incentives, and a <a class=\"af ih\" href=\"https:\/\/hackerone.com\/adobe\" rel=\"noopener ugc nofollow\" target=\"_blank\">public vulnerability disclosure program (VDP)<\/a>, which is open to everyone.<\/p>\n<p id=\"4ad2\" class=\"pw-post-body-paragraph ob oc gu od b hs oe of og hv oh oi oj ok ol om on oo op oq or os ot ou ov ow gn bk\">Last year, Adobe <a class=\"af ih\" rel=\"noopener ugc nofollow\" target=\"_blank\" href=\"https:\/\/blog.developer.adobe.com\/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b\">enhanced its private bug bounty program<\/a>, inviting qualified researchers to apply for the program and work closely with our product security team to responsibly disclosure vulnerabilities found in our products.<\/p>\n<p id=\"4032\" class=\"pw-post-body-paragraph ob oc gu od b hs oe of og hv oh oi oj ok ol om on oo op oq or os ot ou ov ow gn bk\">To further deepen this collaboration and broaden opportunities for the researcher community, Adobe today is announcing the transformation of our public vulnerability disclosure program (VDP) into a <a class=\"af ih\" href=\"https:\/\/hackerone.com\/adobe\" rel=\"noopener ugc nofollow\" target=\"_blank\">paid public bug bounty program<\/a>.<\/p>\n<h2 id=\"7e6c\" class=\"ox oy gu bf oz pa pb dy pc pd pe ea pf ok pg ph pi oo pj pk pl os pm pn po pp bk\"><strong class=\"al\">Adobe VDP Products Now Eligible for Monetary Rewards<\/strong><\/h2>\n<p id=\"3ef0\" class=\"pw-post-body-paragraph ob oc gu od b hs pq of og hv pr oi oj ok ps om on oo pt oq or os pu ou ov ow gn bk\">Adobe is now expanding our investment in the community to make the bug bounty experience accessible for more researchers to get involved in our public bug bounty program and help secure the digital experiences of millions of people worldwide.<\/p>\n<p id=\"30b5\" class=\"pw-post-body-paragraph ob oc gu od b hs oe of og hv oh oi oj ok ol om on oo op oq or os ot ou ov ow gn bk\">Alongside our private bug bounty program, the foundational <a class=\"af ih\" href=\"https:\/\/hackerone.com\/adobe\" rel=\"noopener ugc nofollow\" target=\"_blank\">Adobe Vulnerability Disclosure Program<\/a> has long served as an outlet for security researchers to responsibly and ethically disclose security issues to Adobe. Having refined our program experience and further empowering the resilience of our products, Adobe is now eager to enhance our legacy VDP by transforming it into a paid public bug bounty program. By opening our program to a larger community of researchers, we aim to reinforce further protections for our products, services, and customers.<\/p>\n<p id=\"babc\" class=\"pw-post-body-paragraph ob oc gu od b hs oe of og hv oh oi oj ok ol om on oo op oq or os ot ou ov ow gn bk\">Today, we are excited to announce that researchers participating in our public bug bounty program who successfully identify and report vulnerabilities in the following products will be eligible for monetary rewards:<\/p>\n<h2 id=\"5ff0\" class=\"ox oy gu bf oz pa pb dy pc pd pe ea pf ok pg ph pi oo pj pk pl os pm pn po pp bk\"><strong class=\"al\">Year in Review: Adobe Private Bug Bounty Program<\/strong><\/h2>\n<p id=\"8f96\" class=\"pw-post-body-paragraph ob oc gu od b hs pq of og hv pr oi oj ok ps om on oo pt oq or os pu ou ov ow gn bk\">Over the past year, our Product Security Incident Response Team (PSIRT) scaled its private bug bounty program by onboarding Adobe desktop, web, and mobile apps, doubling bounty payout ranges, and reducing payout times for our bug bounty researchers by 20 percent.<\/p>\n<p id=\"bf3b\" class=\"pw-post-body-paragraph ob oc gu od b hs oe of og hv oh oi oj ok ol om on oo op oq or os ot ou ov ow gn bk\">Since then, Adobe has been actively engaging in the community by celebrating Adobe\u2019s top researchers through the <a class=\"af ih\" rel=\"noopener ugc nofollow\" target=\"_blank\" href=\"https:\/\/blog.developer.adobe.com\/adobe-announces-researcher-hall-of-fame-initiative-for-security-researchers-5e677286dbd6\">Adobe Researcher Hall of Fame initiative<\/a>, participating in live hacking events such as the <a class=\"af ih\" rel=\"noopener ugc nofollow\" target=\"_blank\" href=\"https:\/\/blog.developer.adobe.com\/adobe-recap-2023-ambassador-world-cup-final-four-df701e1a1b12\">2023 Ambassador World Cup (AWC)<\/a> led by <a class=\"af ih\" href=\"https:\/\/www.hackerone.com\/hackers\/brand-ambassador-program\" rel=\"noopener ugc nofollow\" target=\"_blank\">HackerOne Brand Ambassadors<\/a>, and partnering with <a class=\"af ih\" href=\"https:\/\/nahamsec.com\/\" rel=\"noopener ugc nofollow\" target=\"_blank\">Nahamsec<\/a> to support <a class=\"af ih\" href=\"https:\/\/bsidessf.org\/\" rel=\"noopener ugc nofollow\" target=\"_blank\">BSides San Francisco\u2019s<\/a> Bug Bounty Village.<\/p>\n<figure class=\"nm nn no np nq nr nj nk paragraph-image\">\n<div role=\"button\" tabindex=\"0\" class=\"ns nt fj nu bh nv\">\n<div class=\"nj nk qd\"><picture><source srcset=\"https:\/\/miro.medium.com\/v2\/resize:fit:640\/format:webp\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 640w, https:\/\/miro.medium.com\/v2\/resize:fit:720\/format:webp\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 720w, https:\/\/miro.medium.com\/v2\/resize:fit:750\/format:webp\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 750w, https:\/\/miro.medium.com\/v2\/resize:fit:786\/format:webp\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 786w, https:\/\/miro.medium.com\/v2\/resize:fit:828\/format:webp\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 828w, https:\/\/miro.medium.com\/v2\/resize:fit:1100\/format:webp\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 1100w, https:\/\/miro.medium.com\/v2\/resize:fit:1400\/format:webp\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 1400w\" sizes=\"(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px\" type=\"image\/webp\"\/><source data-testid=\"og\" srcset=\"https:\/\/miro.medium.com\/v2\/resize:fit:640\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 640w, https:\/\/miro.medium.com\/v2\/resize:fit:720\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 720w, https:\/\/miro.medium.com\/v2\/resize:fit:750\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 750w, https:\/\/miro.medium.com\/v2\/resize:fit:786\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 786w, https:\/\/miro.medium.com\/v2\/resize:fit:828\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 828w, https:\/\/miro.medium.com\/v2\/resize:fit:1100\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 1100w, https:\/\/miro.medium.com\/v2\/resize:fit:1400\/1*5vDw2RiglZFoAMxpxFm7XQ.jpeg 1400w\" sizes=\"(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px\"\/><img loading=\"lazy\" alt=\"\" class=\"bh mq nw c\" width=\"700\" height=\"468\" loading=\"lazy\" role=\"presentation\"\/><\/picture><\/div>\n<\/div><figcaption class=\"nx ff ny nj nk nz oa bf b bg z du\"><em class=\"qe\">Photo taken at 2023 Ambassador World Cup (AWC) in Argentina.<\/em><\/figcaption><\/figure>\n<p id=\"70a7\" class=\"pw-post-body-paragraph ob oc gu od b hs oe of og hv oh oi oj ok ol om on oo op oq or os ot ou ov ow gn bk\">As a result, we\u2019ve seen massive success with growing engagement across our private program. So far in 2024, we\u2019ve seen an 18 percent increase in overall hacker engagement. Our private bug bounty program has received 317 unique reports and paid out over $200,000 in bounties over the last three months. The PSIRT team has also made substantial efforts to improve the vulnerability disclosure experience for our security researchers, with 96 percent of reports meeting our <a class=\"af ih\" href=\"https:\/\/docs.hackerone.com\/en\/articles\/8505145-response-target-metrics\" rel=\"noopener ugc nofollow\" target=\"_blank\">response standards<\/a> and our program delivering an average time to bounty of 18 days.<\/p>\n<h2 id=\"85be\" class=\"ox oy gu bf oz pa pb dy pc pd pe ea pf ok pg ph pi oo pj pk pl os pm pn po pp bk\"><strong class=\"al\">Get Involved: Help Adobe Build More Secure Products<\/strong><\/h2>\n<p id=\"eb53\" class=\"pw-post-body-paragraph ob oc gu od b hs pq of og hv pr oi oj ok ps om on oo pt oq or os pu ou ov ow gn bk\">As Adobe\u2019s bug bounty programs continue to evolve and scale, we look forward to providing more opportunities to empower security researchers across the globe to engage and collaborate with us to help make a positive impact on securing the digital world.<\/p>\n<p id=\"b114\" class=\"pw-post-body-paragraph ob oc gu od b hs oe of og hv oh oi oj ok ol om on oo op oq or os ot ou ov ow gn bk\">To further encourage participation in Adobe\u2019s public bug bounty program, Adobe is offering researchers additional incentives this year. If you are ready to make an impact in the digital world and level-up your hacking skills, we invite you to <a class=\"af ih\" href=\"https:\/\/hackerone.com\/adobe?type=team\" rel=\"noopener ugc nofollow\" target=\"_blank\">submit a report today on Adobe\u2019s public bug bounty program<\/a> and use code: <strong class=\"od gv\">AdobeLovesBugBounty24<\/strong> to earn an <strong class=\"od gv\">additional 10 percent bounty<\/strong>.<\/p>\n<blockquote class=\"qf\">\n<p id=\"c8e4\" class=\"qg qh gu bf qi qj qk ql qm qn qo ow du\">Submit your bug report with code: <strong class=\"al\">AdobeLovesBugBounty24<\/strong><\/p>\n<p id=\"9767\" class=\"qg qh gu bf qi qj qk ql qm qn qo ow du\">Code expires December 31, 2024.<\/p>\n<\/blockquote>\n<p id=\"4fcc\" class=\"pw-post-body-paragraph ob oc gu od b hs qp of og hv qq oi oj ok qr om on oo qs oq or os qt ou ov ow gn bk\">Additionally, we will be sponsoring the upcoming <a class=\"af ih\" href=\"https:\/\/bsideslv.org\/\" rel=\"noopener ugc nofollow\" target=\"_blank\">BSides Las Vegas<\/a> event! If you\u2019ll be there, come talk to our PSIRT team at the Adobe booth on August 7\u20138 or come find us at the <a class=\"af ih\" href=\"https:\/\/h1.community\/events\/details\/hackerone-hackerone-private-events-presents-recharge-with-hackerone-at-area-15s-asylum-bar-and-arcade\/\" rel=\"noopener ugc nofollow\" target=\"_blank\">HackerOne Recharge<\/a> Day event on August 7.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/blog.developer.adobe.com\/adobe-transforms-public-vulnerability-disclosure-program-to-a-paid-bug-bounty-program-a1f199f8e29e?source=rss----9342990108af---4\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Daniel Ventura, Manager of Product Security Incident Response Team (PSIRT) Generated with Adobe Firefly. As Adobe\u2019s bug bounty programs continue to evolve, we seek to collaborate with more security researchers across the globe to help make a positive impact on securing the digital world at scale. Adobe offers two (2) bug bounty programs: a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9000,"comment_status":"","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[19],"tags":[],"class_list":["post-8999","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-graphics-design"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/posts\/8999","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/comments?post=8999"}],"version-history":[{"count":0,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/posts\/8999\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/media\/9000"}],"wp:attachment":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/media?parent=8999"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/categories?post=8999"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/tags?post=8999"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}