Google Pays $10M in Bug Bounties in 2023

Read Time:45 Second

BleepingComputer has the details. It’s $2M less than in 2022, but it’s still a lot.

The highest reward for a vulnerability report in 2023 was $113,337, while the total tally since the program’s launch in 2010 has reached $59 million.

For Android, the world’s most popular and widely used mobile operating system, the program awarded over $3.4 million.

Google also increased the maximum reward amount for critical vulnerabilities concerning Android to $15,000, driving increased community reports.

During security conferences like ESCAL8 and hardwea.io, Google awarded $70,000 for 20 critical discoveries in Wear OS and Android Automotive OS and another $116,000 for 50 reports concerning issues in Nest, Fitbit, and Wearables.

Google’s other big software project, the Chrome browser, was the subject of 359 security bug reports that paid out a total of $2.1 million.

Slashdot thread.

Read More

ghc-base64-0.4.2.4-28.fc38 ghc-hakyll-4.16.2.0-1.fc38 gitit-0.15.1.1-3.fc38 pandoc-2.19.2-22.fc38 patat-0.8.8.0-2.fc38

Read Time:21 Second

FEDORA-2024-6ad6b9f417

Packages in this update:

ghc-base64-0.4.2.4-28.fc38
ghc-hakyll-4.16.2.0-1.fc38
gitit-0.15.1.1-3.fc38
pandoc-2.19.2-22.fc38
patat-0.8.8.0-2.fc38

Update description:

Security fix for CVE-2023-35936 and CVE-2023-38745

pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745
base64 now packaged in Fedora

Read More