Google has announced the expansion of its initiative to reward cash for identifying vulnerabilities in the Linux kernel. The maximum payout for a new vulnerability and the creation of a working exploit based on it has been increased from $91,000 to $133,000. In addition to the previously used kCTF (Kubernetes Capture the Flag) environment for hacking attempts, new environments have been proposed: one based on the latest stable branch of the regular Linux kernel and another based on the kernel branch that includes extra patches to block common exploit methods.
A bonus of $21,000 is offered for creating exploits that affect the environment with the latest stable kernel branch. An additional $21,000 may be awarded for breaching an environment with enhanced security measures. It is noted that the proposed enhanced security measures can block 9 out of 10 vulnerabilities reported last year and 10 out of 13 exploits claiming a reward.
Source: opennet.ru
