Skip to main content

The Pentagon just paid cash to hackers who found 100+ bugs in its systems

vulnerable pentagon servers the united states department of defense
Considering the nature of its work, it’s no surprise that the Pentagon is of huge interest to hackers, whether state sponsored or pajama wearing (OK, they could be one and the same).

Keen to beef up its cyber security to keep unwelcome visitors at bay, the Department of Defense (DoD) recently launched its first-ever bug bounty program, aptly named “Hack the Pentagon.”

Recommended Videos

Such schemes are pretty common these days, with companies like Google and Facebook inviting so-called “white hat” hackers – those doing it to help rather than cause havoc – to probe their online systems for vulnerabilities.

Set up by the DoD in partnership with HackerOne, a Silicon Valley firm that offers bug bounty services, Hack the Pentagon drew upon the skills of 1,410 white-hat hackers, with the first vulnerability report filed just 13 minutes after the challenge started.

Running for just under a month up until May 12 and focusing on five of its public-facing websites, the DoD’s program turned up a whopping 138 security vulnerabilities deemed “valid and unique,” officials revealed over the weekend. And yes, they’ve already been closed to prevent future trouble.

As a reward for their work, the defense department shared out a bounty worth around $75,000 among the hackers.

Having found so many vulnerabilities, it’s little surprise that the DoD deemed the exercise a success. And, perhaps startled that so many flaws were surfaced, it’s decided to extend the program. Starting this month, its three-pronged approach will include a “vulnerability disclosure process and policy” for the defense department so anyone with information about security weaknesses in its systems, networks, applications, and websites can submit details “without fear of prosecution.”

It also includes incentives in its acquisition policies to encourage greater transparency among contractors, and finally, it’ll expand the bug bounty programs to other parts of the department.

The Pentagon revealed in 2009 it’d spent more than $100 million in a six-month period dealing with damage caused by “daily” cyber attacks on its networks, with the intrusions carried out by everyone from “the bored teenager all the way up to the sophisticated nation-state, with some pretty criminal elements sandwiched in between,” an official said at the time.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Hacking-as-a-service lets hackers steal your data for just $10
A depiction of a hacker breaking into a system via the use of code.

A new (and cheap) service that offers hackers a straightforward method to set up a base where they manage and perform their cyber crimes has been discovered -- and it’s gaining traction.

As reported by Bleeping Computer, security researchers unearthed a program called Dark Utilities, effectively providing a command and control (C2) center.

Read more
Hackers have found a way to log into your Microsoft email account
A depiction of a hacker breaking into a system via the use of code.

Account holders for Microsoft email services are being targeted in a phishing campaign, according to security researchers from Zscaler's ThreatLabz group.

The objective behind the threat actors’ efforts is believed to be the breaching of corporate accounts in order to perform business email compromise (BEC) attacks.

Read more
U.S. federal court system cyberattack is worse than previously thought
A large monitor displaying a security hacking breach warning.

A cyberattack incident that involved the U.S. federal court system infrastructure has been proven to be an “incredibly significant and sophisticated” attack.

This statement is a stark difference from the one initially provided when the situation occurred in 2020.

Read more