Security researcher Joseph Thacker proposed Operation Floodlight, a U.S. government-funded bug-bounty grant program to pay for verified high-severity vulnerabilities affecting critical-infrastructure systems that fall outside existing disclosure programs and commercial bug-bounty scopes. The proposal warns that AI-assisted vulnerability research is lowering discovery costs, increasing the likelihood that serious flaws in internet-facing systems are exploited, privately sold, publicly disclosed without coordination, or never reported.
Floodlight would offer payouts and safe-harbor protections for good-faith researchers, centralized vulnerability validation and disclosure coordination, and possible remediation grants for under-resourced asset owners. The recommended pilot would prioritize healthcare, water, emergency services, and state or local government vendors, using professional triage and expedited handling for vulnerabilities with major public-safety implications; the proposal aligns with broader efforts such as Operation Patchlight and CISA’s critical-infrastructure protection framework.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
Joseph Thacker proposed Operation Floodlight, a U.S. government-funded bounty and disclosure-coordination program for reproducible high- and critical-severity vulnerabilities affecting critical infrastructure that fall outside existing vulnerability-disclosure and bug-bounty scopes. The proposal includes safe-harbor rules, centralized validation, researcher payouts, and a suggested pilot focused on healthcare, water, emergency services, and relevant state or local government vendors.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.