Your business’ toughest competition might be criminal. See why.
Utility navigation bar redirect icon
Portal LoginSupportContact
Search
Close search
Huntress Logo in Teal
  • Platform Overview
    Managed EDR

    Get full endpoint visibility, detection, and response

    Managed EDR

    Get full endpoint visibility, detection, and response

    Managed ITDR

    Protect your Microsoft 365 identities and email environments.

    Managed ITDR

    Protect your Microsoft 365 identities and email environments.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed Security Awareness Training

    Empower your teams with science-backed security awareness training.

    Managed Security Awareness Training

    Empower your teams with science-backed security awareness training.

    Integrations
    Integrations
    Support Documentation
    Support Documentation
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
  • Threats We Stop
    Phishing
    Phishing
    Business Email Compromise
    Business Email Compromise
    Ransomware
    Ransomware
    View Allright arrowView Allright arrow
    Industries We Serve
    Education
    Education
    Financial Services
    Financial Services
    State and Local Government
    State and Local Government
    Healthcare
    Healthcare
    Law Firms
    Law Firms
    Manufacturing
    Manufacturing
    Utilities
    Utilities
    View Allright arrowView Allright arrow
    Tailored Solutions
    MSPs
    MSPs
    Resellers
    Resellers
    SMBs
    SMBs
    Compliance
    Compliance
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
  • Pricing
  • Community Series
    The Product Lab

    Shape the next big thing in cybersecurity together.

    The Product Lab

    Shape the next big thing in cybersecurity together.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    Resources
    Upcoming Events
    Upcoming Events
    ebooks
    ebooks
    On-Demand Webinars
    On-Demand Webinars
    Videos
    Videos
    Whitepapers
    Whitepapers
    Datasheets
    Datasheets
    Cybersecurity Education
    Cybersecurity 101
    Cybersecurity 101
    Cybersecurity Guides
    Cybersecurity Guides
    Threat Library
    Threat Library
    Real Tradecraft, Real Results
    Real Tradecraft, Real Results
    2026 Cyber Threat Report
    2026 Cyber Threat Report
    The Huntress Blog
    Huntress Lands on the Microsoft Marketplace
    Huntress Cybersecurity
    Huntress Lands on the Microsoft Marketplace
    Huntress Cybersecurity
    How Huntress & DEFCERT Are Streamlining CMMC Assessment Prep
    Huntress Cybersecurity
    How Huntress & DEFCERT Are Streamlining CMMC Assessment Prep
    Huntress Cybersecurity
    Live Hacking Into Microsoft 365 with Kyle Hanslovan
    Huntress Cybersecurity
    Live Hacking Into Microsoft 365 with Kyle Hanslovan
    Huntress Cybersecurity
  • Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    The Huntress SOC

    24/7 Security Operations Center

    The Huntress SOC

    24/7 Security Operations Center

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Community

    Get in touch with the Huntress Community team

    Community

    Get in touch with the Huntress Community team

    Compare Huntress
    Bitdefender
    Bitdefender
    Blackpoint
    Blackpoint
    Breach Secure Now!
    Breach Secure Now!
    Crowdstrike
    Crowdstrike
    Datto
    Datto
    SentinelOne
    SentinelOne
    Sophos
    Sophos
    Compare Allright arrowCompare Allright arrow
  • HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    Partners
    MSPs

    Join our partner community to deliver expert-led managed security.

    MSPs

    Join our partner community to deliver expert-led managed security.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Tech Alliances

    Driving innovation through global technology Partnerships

    Tech Alliances

    Driving innovation through global technology Partnerships

    Microsoft Partnership

    A Level-Up for Your Business Security

    Microsoft Partnership

    A Level-Up for Your Business Security

  • Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Awards
    Awards
    Contact Us
    Contact Us
  • Portal Login
  • Support
  • Contact
  • Search
  • Get a Demo
  • Start for Free
Portal LoginSupportContact
Search
Close search
Get a Demo
Start for Free
HomeBlog
Bug Bounties for the 99%
Published:
September 27, 2022

Bug Bounties for the 99%

By:
Garrett Gross
Share icon
Glitch effectGlitch effectGlitch effect

Intro by Andrew Morgan, Founder of Right of Boom Cyber Summit.

March 26, 2020, and July 2, 2021, are two dates that will be seen as turning points for the way managed service providers (MSPs) run their businesses.

The SolarWinds SUNBURST (2020) and the Kaseya ransomware attack (2021) put such a spotlight on supply chain attacks that both CISA and cyber insurance carriers became incredibly vocal about the massive risk managed service providers can have on their end customers. These supply chain risks were also highlighted with Exchange ProxyShell and a number of internet-facing firewall vulnerabilities with Fortinet, SonicWall and Pulse Secure.

Many MSPs are incredibly well-run, have a security-first mindset and follow frameworks and best practices, and have implemented policies to mitigate risk within their and their clients’ environments. That said, the aforementioned events created incredible hardship for many MSPs and their clients, while the MSPs themselves were held accountable for using a vulnerable third-party piece of software. As a result, their insurance premiums skyrocketed or coverage was dropped.

On average, MSPs use more than 17 applications to run their business and deliver their services. But they don’t have the internal capabilities to continuously audit the application security of their vendors, nor are vendors in the MSP ecosystem on the margin adopting application security programs like BSIMM, implementing vulnerability disclosure programs (VDPs) or offering bug bounty programs that incident security researchers to find issues within the applications MSPs rely on. 

***

The State of Affairs for Security Researchers

In the security research community, we’re actually pretty ineffective at security research in regard to the tech landscape.  

Why? Because as researchers, we’re heavily outnumbered by the threats out there, forcing us to pick and choose what we work on.

Aside from the true altruists in our community, many researchers are attracted to who can pay the most, either via a position on a research team or through an externally facing program that offers cash awards to those who can find the bugs (before attackers do).

These are commonly referred to as “bug bounty programs" and, as expected, the most active bug bounty programs are run by the most successful tech businesses. They get the lion’s share of the attention from the research community.

Unfortunately, that leaves a large swath of the tech landscape (small to medium-sized businesses [SMBs], state/local government, open-source software projects, etc.) left to fend for themselves since there traditionally isn't very much money—if any—to be had by finding those vulnerabilities.

Open-Source Software: An Attractive Target for Hackers

Well, wouldn’t you know it: open-source software is everywhere, and our reliance on it is at a scale that we likely didn't account for.

When we find exploitable vulnerabilities present in software as widely used as Secure Shell Protocol (SSH), Secure Sockets Layer (SSL), etc., it can cause panic because it is difficult to wrap our brains around use at that scale.  

You can also guarantee that these exploits will be weaponized immediately following disclosure (via tools like Metasploit, Cobalt Strike, etc.), so due to the lack of technical skills required to operate these tools and launch such attacks, the incoming wave of activity can be overwhelming to even those with a substantial security presence.

The cleanup of one such exploit, Log4Shell (an exploit of a commonly used web server logging utility), has been referred to as “the largest mass scale cyber response in history” by Rob Silvers, undersecretary for policy at the U.S. Department of Homeland Security.

Regarding the threat itself, he asserts that

"[...] it is likely that organizations are going to be dealing with continued Log4j exposure for years to come, maybe a decade or longer."

I would posit that this is only the beginning of this type of activity, and due to the reliance on open-source software in critical infrastructure and national security systems, these supply chain attacks will only become more prevalent.

Bug Bounty Programs

In the wake of these supply chain issues, Google has announced a bug bounty program specifically for open-source software. Capitalizing on the fervor associated with these recent security events, Google aims to further incentivize security researchers in spending time investigating design issues that may lead to exploitable vulnerabilities.

Bug bounties are becoming more prevalent these days, and the amount that companies are willing to pay out keeps growing. Google paid out more than $8.7M in 2021, and Apple currently offers up to $1M for finding their most critical flaws.

image1-3

Special shout-out to Google for including hacker easter eggs in their payout matrix. Are you 1337 or are you 31337?

There are even companies out there like Hackerone and BugCrowd that enable companies that may not have the capabilities to manage their own bug bounty programs by connecting them with freelance security researchers and brokering the payout process.

It makes sense, though. The bounties paid for finding these vulnerabilities pales in comparison to the immeasurable financial disaster that an attack could precipitate.  

Companies are happy to pay these relatively reasonable bounties in exchange for responsible disclosure of how the exploit works. For the security researcher, this can prove to be a very lucrative career, as we’ve seen nine individuals claim over $1M in bounties from the aforementioned bug bounty aggregator, Hackerone.

So Where Does That Leave the 99%?

There’s a problem here, though. With 99% of US businesses (~32 million) classified as “small”, most of them don't have the means to effectively manage security, let alone the resources required to manage a bug bounty program and the money to pay these bounties out. Yet they are still faced with the same cyber threats as the other 1% and, unlike those in the enterprise, are not favored to withstand the potential fallout.

To further complicate the issue, the folks that most small businesses turn to for their IT and security services, MSPs, are currently prime targets for threat actors. This is due, primarily, to two factors:

  • MSPs are a single entry point for many more SMBs. As we’ve seen in the past, with such notable events as the Kaseya breach, the tools that MSPs use to provide visibility and reach across a large client base can be used against them. Even if the MSP has a comprehensive security stack and is seemingly doing all the right things, a breach can still happen, as we’ve seen in the past.
  • Most MSPs are small businesses, too. Just like the SMB as a whole, there is only a small percentage of MSPs that have invested a significant amount of resources into security—and with more than half (57%) of MSPs in the US having been around for less than five years, they are prime targets for threat actors. They are more likely to be ill-equipped to handle any sort of attack from a people, process and technology standpoint, so the chances of them paying at least a portion of the ransom is high.  

And that’s where the Dutch Institute for Vulnerability Disclosure (DIVD) comes in.

Earlier this year, we partnered with our friends from Appgate, Axcient, Blumira, MSPCFO, OITVoip, Servosity, Taylor Business Group and Unveil Security Group to support DIVD financially as well as create/fund a bug bounty program focused on MSPs. 

The aim is to fund the payouts of these bug bounties, ensuring that they are on par with the larger programs in an effort to attract the same level of activity that is usually afforded to the larger companies only.  

Hopefully, more security vendors will recognize the benefits of supporting initiatives like this. If we all pitch in, we may stand a chance of leveling the playing field in regards to everyone’s ability to respond to threats.

Learn More

If there’s one truth that has withstood the test of time in cybersecurity, it’s this: we’re better together.

That’s why we’re proud to offer the Huntress Neighborhood Watch Program: a collection of resources and programs to help elevate the broader security community—with a special focus on the 99% of businesses that are often underserved.

Categories
Cybersecurity Education
Summarize this postClose Speech Bubble
ChatGPTClaudePerplexityGoogle AI

See Huntress in action

Our platform combines a suite of powerful managed detection and response tools for endpoints and Microsoft 365 identities, science-backed security awareness training, and the expertise of our 24/7 Security Operations Center (SOC).

Book a Demo
Share
Facebook iconTwitter X iconLinkedin iconDownload icon
Glitch effect

You Might Also Like

  • Huntress Donates $100,000 to DIVD Bug Bounty Program to Elevate SMB Cybersecurity, Calls on MSP Vendors to Follow Suit

    We believe it’s time for MSP vendors to level up cybersecurity community efforts, so we’re taking the first step with a $100,000 contribution to DIVD.
  • Leaving the Silo: MSP Vendors Give Back

    Learn the latest about our initiative with the Dutch Institute for Vulnerability Disclosure and how you can get involved.
  • Huntress’ Commitment to the Cybersecurity Community

    We founded Huntress with a commitment to elevating the cybersecurity community as a guiding principle. Here are some of the ways we strive to make a difference.
  • The Health Sector is Under Attack. But You Can Fight Back.

    Healthcare organizations are facing cyber threats at an alarming rate, and as the U.S. Department of Health and Human Services (HHS) introduces new measures for cybersecurity, it’s also time for small- and mid-sized organizations to be proactive in their defense.
  • Scaling To Protect the 99%

    Learn about the latest platform changes and updates as Huntress continues to scale to protect the 99%.
  • The Top 3 Cyber Challenges for Mid-Market Businesses

    Uncover top cyber challenges for mid-sized businesses in 2023; from lack of time and skills, human vulnerabilities, and budget constraints.
  • Mid-Sized Businesses vs. The Threat Landscape in 2023

    A survey of mid-sized businesses revealed common cybersecurity vulnerabilities. Learn what they are and how to improve your security posture in 2023.
  • Zero-Day Vulnerabilities in Platforms Could Leave MSPs Exposed

    We unveil zero-day vulnerabilities we discovered in virtual event platforms used in MSP/Fortune 500 communities, plus some insight on supply chain attacks.

Sign Up for Huntress Updates

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.
Privacy • Terms
By submitting this form, you accept our Terms of Service & Privacy Policy
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Huntress Managed Security PlatformManaged EDRManaged EDR for macOSManaged EDR for LinuxManaged ITDRManaged SIEMManaged Security Awareness TrainingBook a Demo
PhishingComplianceBusiness Email CompromiseEducationFinanceHealthcareManufacturingState & Local Government
Managed Service ProvidersResellersIT & Security Teams24/7 SOCCase Studies
BlogResource CenterCybersecurity 101Upcoming EventsSupport Documentation
Our CompanyLeadershipNews & PressCareersContact Us
Huntress white logo

Protecting 215k+ customers like you with enterprise-grade protection.

Privacy PolicyCookie PolicyTerms of UseCookie Consent
Linkedin iconTwitter X iconYouTube iconInstagram icon
© 2025 Huntress All Rights Reserved.

Join the Hunt

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy