GitHub Slashes Public Bug‑Bounty Payouts, Shifts Top Rewards to Invite‑Only VIP Tier
What Happened — Effective July 27 2026, GitHub reduced the cash awards for all public‑bug‑bounty submissions by at least 50 %. Critical findings now receive a flat $10,000, while the newly‑created invite‑only VIP tier pays $30,000 + for the same severity. Reports filed before the change keep the original terms.
Why It Matters for Compliance & Audit Readiness
- SOC 2’s CC6.1 (Vulnerability Management) expects organizations to demonstrate a systematic process for identifying and remediating security weaknesses; a robust external‑research program is a key evidence source.
- Reducing public payouts may lower the volume of disclosed findings, making it harder to prove continuous monitoring and timely remediation to auditors.
- Verisq’s Control Mapping capability helps you map any change in vulnerability‑management incentives to the specific SOC 2 controls, collect continuous evidence, and keep your audit trail defensible.
Who Is Affected — SaaS platforms, cloud‑hosting services, and any organization that relies on external bug‑bounty programs for security testing.
Recommended Actions
- Review your vulnerability‑management policy to ensure external reporting channels remain effective despite reduced incentives.
- Map the GitHub bounty change to SOC 2 CC6.1 and CC6.2 controls; capture evidence of any supplemental internal testing you add to compensate.
- Document the policy shift in your risk register and update your continuous‑compliance dashboards.
Source: The Hacker News
Technical Notes — No new vulnerability or exploit disclosed; the change is a program‑policy adjustment affecting the economics of external security research.