{"id":37565,"date":"2020-10-08T22:40:30","date_gmt":"2020-10-08T22:40:30","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/"},"modified":"2020-10-08T22:40:30","modified_gmt":"2020-10-08T22:40:30","slug":"want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/","title":{"rendered":"Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers"},"content":{"rendered":"<p>If you&#8217;re designing a security bug bounty for your organization&#8217;s products, by all means get the lawyers to take a look, but keep their hands off the keyboard. If it&#8217;s one thing flaw-finders find too tedious to deal with, which will put them off finding holes in your defenses, it&#8217;s legalese \u2013 and these are people who otherwise spend all day combing reverse-engineered code for typos.<\/p>\n<p>This point came up during a panel discussion <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.cisa.gov\/cybersummit-2020-day-four-defending-our-democracy\">this week<\/a> at a summit organized by the US government&#8217;s Cybersecurity and Infrastructure Security Agency (CISA).<\/p>\n<p>Chlo\u00e9 Messdaghi, veep of strategy at infosec training firm Point3, said she&#8217;s encountered bounty programs that look more like they&#8217;re intended for the legal team than the security community.<\/p>\n<p>&#8220;You want to be as clear, concise, and short as possible,&#8221; Messdaghi said. &#8220;We come across bug bounty programs, and sometimes it is written by an attorney for an attorney to understand it.&#8221;<\/p>\n<p>Not everyone understands the legal jargon, particularly if they are written in a foreign language \u2013 not every bug hunter speaks English, Messdaghi noted \u2013 which means rules and limits can be misunderstood and that leads to arguments and disagreements and worse. The VP also said that once a program is in place, whoever&#8217;s fielding the incoming vulnerability reports should know exactly who to send them to on the product or security teams. Seems simple but corporations get this wrong.<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2019\/11\/06\/shutterstock_bug.jpg?x=174&amp;y=115&amp;crop=1\" width=\"174\" height=\"115\" alt=\"Software bug \"><\/p>\n<h2 title=\"'A secure dev lifecycle has a much higher ROI than letting the public do the bug detection work for you'\">Microsoft forked out $13.7m in bug bounties. The reward program&#8217;s architect thinks the money could be better spent<\/h2>\n<p><a href=\"https:\/\/www.theregister.com\/2020\/08\/04\/microsoft_137_bug_bounties\/\"><span>READ MORE<\/span><\/a><\/div>\n<p>Other panelists noted that companies don&#8217;t have to go all in when launching their bug bounty programs. Jack Cable of CISA suggested that companies can start off by only asking for reports for a small subset of their online footprint or product base, and then grow from there.<\/p>\n<p>&#8220;What you can do is start small,&#8221; advised Cable, an election security technical advisor at the government agency. &#8220;So it does not have to be everything under your organization.&#8221;<\/p>\n<p>The panel also touched on election computer security, and the progress made between the infosec community and voting machine manufacturers in terms of working more closely together in a constructive manner. Joshua Franklin, CTO of the US Election Assistance Commission, bemoaned the lack of research being done on many of the latest voting and ballot-handling systems.<\/p>\n<p>&#8220;I hope that we have a clear path for well-intentioned research to be conducted on all voting systems without running afoul of Computer Fraud and Abuse Act,&#8221; he said referring to America&#8217;s <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2020\/09\/15\/voatz_bug_hunting_letter\/\" rel=\"noopener noreferrer\">problematic anti-hacking law<\/a>. &#8220;The latest decade of systems has not received the scrutiny that past generations have.&#8221;<\/p>\n<blockquote class=\"pullquote\" readability=\"5\">\n<p>The latest decade of voting systems has not received the scrutiny that past generations have<\/p>\n<\/blockquote>\n<p>Others, however, saw some progress being made. Chris Wlaschin, veep of systems security at voting machine maker Election Systems and Software, said there is a &#8220;warming&#8221; of relations between machine vendors and white-hat hackers.<\/p>\n<p>&#8220;The relationship between security researchers and the election tech providers was a bit frosty, but it is warming up,&#8221; he said, quite possibly referring <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2020\/08\/06\/black_hat_ess_bugs\/\" rel=\"noopener noreferrer\">to this<\/a>. &#8220;We are warming that relationship, and I think it is a great move in the right direction.&#8221;<\/p>\n<p>Regardless, it seems election officials would like to see both camps set aside their differences and get to work on rooting out potential security vulnerabilities in election-related systems sooner than later.<\/p>\n<p>&#8220;The big reality that people need to understand,&#8221; said Spencer Wood, CIO for Ohio&#8217;s Secretary of State, &#8220;is the bad guys are every single day looking for those vulnerabilities.&#8221; \u00ae<\/p>\n<p> READ MORE <a href=\"https:\/\/go.theregister.com\/feed\/www.theregister.com\/2020\/10\/08\/cisa_bug_bounty_panel\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Plus: Experts talk voting machine security, &#8216;warming&#8217; of relations with infosec community If you&#8217;re designing a security bug bounty for your organization&#8217;s products, by all means get the lawyers to take a look, but keep their hands off the keyboard. If it&#8217;s one thing flaw-finders find too tedious to deal with, which will put them off finding holes in your defenses, it&#8217;s legalese \u2013 and these are people who otherwise spend all day combing reverse-engineered code for typos.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":37566,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-37565","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-10-08T22:40:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"174\" \/>\n\t<meta property=\"og:image:height\" content=\"115\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers\",\"datePublished\":\"2020-10-08T22:40:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/\"},\"wordCount\":619,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/\",\"name\":\"Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers.jpg\",\"datePublished\":\"2020-10-08T22:40:30+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/","og_locale":"en_US","og_type":"article","og_title":"Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-10-08T22:40:30+00:00","og_image":[{"width":174,"height":115,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers","datePublished":"2020-10-08T22:40:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/"},"wordCount":619,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/","url":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/","name":"Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers.jpg","datePublished":"2020-10-08T22:40:30+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/want-to-set-up-a-successful-bug-bounty-make-sure-you-write-it-for-the-flaw-finders-and-not-the-lawyers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/37565","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=37565"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/37565\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/37566"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=37565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=37565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=37565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}