
The number of reports filed under the "security vulnerability bounty program" operated by Genians has more than doubled over the past year, driven by advances in artificial intelligence (AI) technology.
Cybersecurity specialist Genians said Tuesday that, based on the results of its security vulnerability bounty program in the first half of this year, the number of reported vulnerabilities rose about 129% from a year earlier, while bounty payouts increased about 1,046%. Also known as a "bug bounty," the security vulnerability bounty program is a system that pays rewards to white-hat hackers who discover security weaknesses in software or web services. In 2022, Genians became the first in Korea's security industry to launch its own bug bounty program.
The growth in vulnerability reports reflects the convergence of the popularization of AI technology and the emergence of high-risk vulnerabilities. As AI technology has advanced rapidly, white-hat hackers' use of AI has also increased significantly. In particular, detection activity that uses AI to automatically find security vulnerabilities is establishing itself as a new trend.
Genians proactively adopted a method that links white-hat hackers' participation and rewards to its Vulnerability Disclosure Policy (VDP) and Coordinated Vulnerability Disclosure (CVD) procedures. Rather than stopping at simple remediation, the company transparently discloses detailed information on resolved vulnerabilities through the official channels of individual products. Through this, it helps client companies carry out updates quickly and safely without the risk of vulnerability exposure.
Since February of this year, Genians has expanded its bug bounty program to all of its products and services, accepting reports from white-hat hackers worldwide on an ongoing basis through official Korean- and English-language pages. In particular, the company links its company-wide security research service with global community platforms to manage and disseminate product vulnerabilities more systematically and broadly. As part of this, it carries out security advisory measures using the "Security Advisories" feature of GitHub, a global open-source platform. For discovered vulnerabilities, it obtains CVE IDs, an international standard, to transparently disclose product reliability and the status of prompt remediation.
"The results of operating the bug bounty program go beyond merely the achievement of discovering vulnerabilities; they prove Genians' own unique defensive capabilities to proactively respond to the sophisticated threats of the AI era," said Kim Kye-yeon, Chief Technology Officer of Genians and head of its U.S. subsidiary. "Going forward, we will firmly establish our own bug bounty as a global-standard CVD and VDP system to provide reliable products to customers worldwide and lead the healthy development of the global security ecosystem."






