All News
23 July 2026IT News

GitHub Reduces Public Bug Bounty Payouts, Introduces VIP Tier for Top Rewards

GitHub is set to reduce its public bug bounty payouts by at least half across all severity levels, with critical findings now capped at $10,000, while introducing a VIP tier with higher rewards, a move that may impact Australian IT professionals and students, including those pursuing certifications like Security+ at institutions such as Wepro Technology.

In a significant development for the global IT community, GitHub has announced that it will be reducing its public bug bounty payouts, effective July 27, 2026. This change will see payouts cut by at least half at every severity level, with critical findings, which were previously rewarded with $20,000 to $30,000 or more, now being capped at a fixed $10,000.

The reduction in payouts is expected to have implications for IT professionals and security researchers around the world, including those in Australia, who have been actively contributing to GitHub's bug bounty program. However, it's worth noting that reports filed before the July 27 deadline, including those currently in GitHub's triage queue, will retain the previous payout terms, providing a window of opportunity for those who have already submitted their findings.

The introduction of a permanent invite-only VIP tier is also part of GitHub's new strategy, with this tier offering payouts of $30,000 or more for critical findings. This move is seen as an attempt to incentivize top security researchers to continue contributing to the platform, while also acknowledging the value of their expertise and the importance of their role in maintaining the security of GitHub's ecosystem.

For Australian IT professionals and students, this development serves as a reminder of the evolving landscape of cybersecurity and the need for ongoing training and skill development. As the demand for skilled cybersecurity professionals continues to grow, institutions such as Wepro Technology play a crucial role in providing relevant certifications and training programs, including Security+, to help individuals stay up-to-date with the latest threats and technologies.

The reduction in public bug bounty payouts may also prompt some security researchers to explore alternative programs or focus on other areas of cybersecurity, such as compliance or risk management. Nevertheless, the introduction of the VIP tier is likely to attract top talent, and the overall impact of these changes on the cybersecurity community will be closely watched in the coming months.

As the IT industry in Australia continues to grow and mature, developments like GitHub's revised bug bounty program serve as a reminder of the global nature of cybersecurity and the need for collaboration and knowledge-sharing across borders. Whether you're a seasoned security professional or just starting out in the field, staying informed about the latest trends and developments is essential for success in this rapidly evolving landscape.

Source
The Hacker NewsView original
Newsletter

Stay ahead in IT

Join 200+ Australian IT professionals getting weekly insights delivered to their inbox.

  • Weekly IT news & insights
  • New course announcements
  • Free quiz updates

Your email

No spam, ever · Unsubscribe anytime

Ask anything!