GitHub has overhauled its bug bounty program, reducing public-program payouts, replacing variable reward ranges with fixed amounts by severity, and creating a permanent invite-only VIP tier for researchers who consistently deliver high-impact findings. The company said the changes are intended to reduce triage pressure, improve researcher experience, and strengthen collaboration with trusted contributors, with the new structure applying to reports submitted on or after July 27, 2026.
Under the revised model, top rewards are being concentrated in the VIP program, which offers higher payouts, faster engagement, and closer access to GitHub’s security engineering team, while public submissions will face stricter quality controls. GitHub is also requiring stronger HackerOne signal from participants to curb low-effort and AI-generated reports, reflecting broader industry concern that automated and commoditized vulnerability discovery is increasing report volume while making validated, product-specific findings more valuable.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
GitHub announced major changes to its bug bounty program, including a permanent invite-only VIP tier for high-impact researchers, fixed public bounty payouts by severity, and a HackerOne signal requirement intended to reduce low-quality submissions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcexakep.ru
Open sourcesecurityonline.info
Open sourcehelpnetsecurity.com
Open sourcethehackernews.com
Open sourcegithub.blog
Open sourcehackerone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.