Facebook is expanding its bug bounty program to third-party apps and websites that might expose user tokens improperly.
Disclose.io provides a clear legal framework to protect organizations and researchers engaged in vulnerability disclosure programs. The goal is to protect those engaged in good-faith security research from legal action.
Microsoft will do more than pay researchers bounties for finding and reporting vulnerabilities in Microsoft Account and Microsoft Entra ID in its Microsoft Identity Bounty Program. The company also wants vulnerabilities in select OpenID standards.
Uber has updated its bounty program to provide security researchers with clarity on what good faith research looks like.