Skip to content
June 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • 25 of the top-ranking hackers worldwide take part in Hack the Air Force 2.0
  • News

25 of the top-ranking hackers worldwide take part in Hack the Air Force 2.0

Do Son December 24, 2017 4 minutes read
Add as a preferred
source on Google

December 23 White hat hackers and the U.S. military network experts co-organized a 9-hour hacker marathon bug bounty – the latest Air Force hacking program H1-212. Twenty-five top hackers from the United States, Canada, the United Kingdom, Sweden, the Netherlands, Belgium and Latvia, together with several military network experts, once again infiltrated the United States Air Force’s key networks to explore various online platforms that could potentially give the U.S. military more than 300 branches Operate a security breach that poses a risk.

By USAF [Public domain], via Wikimedia Commons

HackerOne, a network security platform, is in charge of this event and will pick out 50 of the world’s top 50 participants from the world.

H1-212 Bounty Program Outcome

Contestants discovered two security breaches within the first 30 seconds of the race and 55 security breaches in the following 9 hours, for a total amount of $26,883. One of the high-risk security holes gave two hacker discoverers a direct $ 10,650 bonus – the largest single solo bounty ever issued by the U.S. government. In the weeks following the bounty program, several more participants reported successively related security holes that were not discovered during the H1-212 campaign.

Peter Gold, the chief information security officer of the U.S. Air Force, said in a statement: “This brouhaha has given the U.S. military an eye-opener and the cooperation of the U.S. Air Force and the human resource defense and defense system of partner countries has brought extremely invaluable costs benefit.”

“In the first round of the bounty program, all the tasks are done online and it can take a few hours or even days to get the Air Force’s response, and in H1-212 the response from the staff is even keener, and because of the direct contact with these workers, participants are also more motivated to find clues about the Bug.”

U.S. Air Force First Bug Bounty Program

The Air Force’s first Hack reward program, Hack the Air Force, is scheduled to end in June 2017. At that time, the Department of Defense invited security researchers, military personnel, “The Five Eyes” (the United States, Britain, Canada, Australia and New Zealand) Intelligence Alliance white hat hackers “invaded” the Air Force network.272 white hat hackers found 207 valid bugs in the Air Force network, more than the Defense Ministry and the U.S. Army.

  • The Department of Defense’s Hack the Pentagon program found a total of 138 vulnerabilities.
  • The U.S. Army “Hack the Army” found a total of 118 holes.

US Army Bug Bounty Program Achievements

The so-called Bug Bounty program refers to recruiting “ethical hackers (cybersecurity experts who actually simulate hacking”) or white hat hackers looking for security holes in the computer networks of the relevant organizations. The specific nature of security vulnerabilities is not required and can, therefore, cover a wide range of risks, ranging from low-risk vulnerabilities to high-risk risks that could lead to the overall network being paralyzed and even sensitive information being leaked.

HackerOne Organizer

Alex Rice, chief technology officer of HackerOne, said: “This joint event organized by the U.S. Department of Defense and HackerOne, through the Bug Bounty Challenge and the subsequent Security Vulnerabilities Discovery Program, addresses a total of more than 3,000 Security breach Hackers received more than $ 300,000 in prize money for their contribution, a measure not only exceeding participants’ expectations but also saving millions of dollars in security funding for the U.S. Department of Defense.

To date, HackerOne has been responsible for organizing four rounds of government bug-bounty packages, including Hack the Air Force 2.0 (soon to be launched), another larger bug bounty program.

HackerOne chief executive Martin – McCarthy said in an interview, he believes that white hat network experts, part of the “talent system” has great potential applications. The Bug Bounty program provides a new look for organizations that fail to spot their own vulnerabilities in time. By focusing on software solutions from a potential criminal’s perspective, participants will be able to quickly find the security flaw they are most likely to exploit. In the past, people secretly sought security programs in small groups. Now we are trying to prove that, in order to further enhance the level of security, we must invite the forces from the outside world as reinforcements. ”

Larger Bug bounty program is about to start

The H1-212 incident also opened the curtain on a larger Bug Hack program, Hack the Air Force 2.0.

Hack the Air Force 2.0 will be officially launched on January 1, 2018. Unlike the original Air Force Bug Bounty program, version 2.0 will be open to Citizens of Five Alliance countries – specifically Australia, Canada, New Zealand, the United Kingdom and the United States, plus NATO countries and Sweden. This makes the 2.0 program the most open bug rewards program ever made.

Reference: infosecurity-magazine

Related coverage

  • BlackTDS: new Traffic Distribution System
  • The CoWIN Portal Breach: A Crisis in Indian Data Security
  • iOS 26 Unveils “Captive Assist”: Seamless Public Wi-Fi Login Across All Your Apple Devices
  • FCC may prevent mobile providers from receiving federal subsidies if they use Huawei & ZTE equipment
  • The Notarized Nightmare: New MacSync Stealer Bypasses Gatekeeper to Hijack Mac Devices

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Tags: Hack the Air Force 2.0

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-34908CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi...
  • CVE-2026-34909CVSS 10.0
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS...
  • CVE-2026-34910CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi...
  • CVE-2025-67038CVSS 9.8
    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write...
  • CVE-2024-23692CVSS 9.8
    Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This...
  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-48907
    A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated...
  • CVE-2026-20253CVSS 9.8
    In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or...
  • CVE-2026-4020CVSS 7.5
    The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
  • CVE-2026-20182CVSS 10.0
    May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and...
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-55454CVSS 9.9
    Appsmith is a platform to build admin panels, internal tools, and dashboards....
  • CVE-2026-55570CVSS 9.0
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it...
  • CVE-2026-50551CVSS 9.9
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan...
  • CVE-2026-54158CVSS 9.9
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the...
  • CVE-2026-52813CVSS 10.0
    Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization...
  • CVE-2026-52806CVSS 9.9
    Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs...
  • CVE-2026-45689CVSS 9.1
    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0,...
  • CVE-2026-45688CVSS 9.1
    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0,...
  • CVE-2026-54067CVSS 9.9
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS...
  • CVE-2026-53943CVSS 9.6
    Ghost is a Node.js content management system. From until 6.37.0, when Ghost...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.