ZeroHour
CyberScooppublished ()ingested @snlyngaas

House panel advances State Department bug bounty bill

criticalPolicy & legalimportance 55
Full article942 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The House Foreign Affairs Committee advanced a bill in the latest effort to encourage agencies to use ethical hackers to secure their networks.

State Department bug bounty
A child watches as U.S. Secretary of State Mike Pompeo speaks to staff and families from U.S. Embassy Riyadh, in Riyadh, Saudi Arabia, on April 29, 2018. The House advanced a measure that would create a bug bounty program at the State Department. (State Department photo/ Public Domain)

The House Foreign Affairs Committee on Wednesday advanced a bill that would establish a bug bounty program at the State Department, the latest effort by lawmakers and security gurus to encourage agencies to use ethical hackers to secure their networks.

The Hack Your State Department Act would task the Secretary of State with setting up a vulnerability disclosure process for researchers to hunt for and disclose flaws in the department’s public-facing websites and applications. The program, which would emulate the Hack the Pentagon project the Defense Department carried out in 2016, would pay researchers for finding vulnerabilities of which State officials were unaware.

“Any agency or private sector company should have an independent way of testing security,” Rep. Ted Lieu, D-Calif., the bill’s sponsor, told CyberScoop. “This is one of the ways to do it – get an independent check on the strength of the cybersecurity system.”

“A lot of these systems – no matter how smart you think you are – there are always hackers out there who can figure out ways to breach them,” Lieu added.

Mark Kuhr, co-founder and CTO of Synack, a cybersecurity-testing firm that expanded the Pentagon’s bug-bounty program to cover sensitive IT assets, said he was encouraged by “positive momentum behind crowdsourced security testing.”

“The most successful programs vet for the most skilled and trustworthy hackers and aim for reducing the number of vulnerabilities over time as their systems become more hardened to attack,” Kuhr told CyberScoop. “We hope to see these considerations kept in mind as the bill advances.”

Lieu’s bill calls for establishing a bug bounty program within a year, but Katie Moussouris, a bug bounty expert and founder of consultancy Luta Security, cautioned that it would take longer than that.

Rather than establishing timelines for setting up bug bounties, “Congress should be funding an overhaul of internal capabilities” at federal agencies to make them more secure, Moussouris said.

“Bug bounties should only be used in circumstances where you’ve done your best to find and fix issues yourself, not as a replacement for due diligence and process, and not as a replacement for professional penetration testing,” Moussouris, who helped stand up the Hack the Pentagon program, told CyberScoop.

The Hack Your State Department Act is part of a series of legislation that aims to get federal agencies to embrace bug bounties, which are common practice in the private sector. The Senate last month passed legislation that would put $250,000 toward setting up a bug bounty program at the Department of Homeland Security. Lieu has introduced a companion bill in the House.

Lieu sees the legislation as part of a larger effort to open federal networks to ethical hacking.

“One reason we’re doing this is to raise the profile of this issue in general,” Lieu told CyberScoop. “Hopefully, other agencies will look at this and go, ‘Hey, we should try doing that.’ ’’

Malicious hackers have targeted State Department networks in recent years. In 2014, the department was forced to temporarily shut down its unclassified email system after suspected Russian hackers had breached it.

More Scoops

Chairman Rick Crawford, R-Ark., center, and ranking member Rep. Jim Himes, D-Conn., right, conduct the House Select Intelligence Committee hearing titled “Worldwide Threats Assessment,” in Longworth building on March 26, 2025. (Tom Williams/CQ Roll Call)

House intel bill includes provisions on state and local threat intelligence, election security, AI

The House Intelligence Committee advanced its fiscal 2027 authorization legislation Monday.

OpenAI and Anthropic said they turned over their models to government researchers, who found an array of previously undiscovered vulnerabilities and attack techniques. (Image via Getty)

HackerOne rolls out industry framework to support ‘good faith’ AI research

(L-R) Rep. Nick LaLota R-N.Y., Rep. Tony Gonzales, R-Texas, Rep. Marjorie Taylor Greene, R-Ga. and Rep. Andrew Garbarino, R-N.Y., listen during a hearing with the House Committee on Homeland Security on Jan. 30, 2024. (Photo by Anna Moneymaker/Getty Images)

House panel approves cyber information sharing, grant legislation as expiration deadlines loom

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/state-department-bug-bounty-bill-advances/