Monash University launched a bug bounty program five
years ago to address the persistent challenge of effectively identifying and
managing known and unknown vulnerabilities. This initiative aimed to enhance
cybersecurity resilience by encouraging ethical hackers to uncover flaws before
malicious actors could exploit them.
In this presentation, we will explore the
origins of the problem, our perspective on vulnerability management, the
evolution of our bug bounty program, and our successes and setbacks along the
way.
We will also discuss how we hold vendors accountable for fixing
vulnerabilities, driving collective responsibility toward a safer digital
ecosystem.