LG Uplus is launching a global bug bounty programme from Aug. 24 in partnership with HackerOne, the world's largest bug bounty platform. Information security officials discuss the operation of the global bug bounty programme. [Photo: LG Uplus]

LG Uplus will operate a global bug bounty programme from the 24th in partnership with HackerOne, the world's largest bug bounty platform.

A bug bounty is a system that pays rewards to white-hat hackers who find security vulnerabilities in a company's or institution's services and IT infrastructure. External experts look for weaknesses in an environment similar to real services, allowing security risks to be identified early and addressed.

The programme will cover all of LG Uplus' services, including mobile, internet and enterprise services. It aims to identify potential vulnerabilities that are difficult to find through domestic security verification alone by leveraging the global white-hat hacker community.

LG Uplus said that as services connected to overseas infrastructure increase, including roaming, cloud and AI services, security threats are also expanding beyond borders. It formed a partnership with HackerOne and prepared a global bug bounty programme as the first domestic telecoms company to do so. HackerOne is a bug bounty platform with about 2.4 million white-hat hackers worldwide.

Only experienced white-hat hackers who have completed identity checks and capability verification will participate in LG Uplus' global bug bounty in a private format. LG Uplus will receive continuous reports of vulnerabilities from them to detect threats and analyse and improve vulnerabilities.

LG Uplus has jointly operated a domestic bug bounty system with the Korea Internet & Security Agency (KISA) since October 2024. It identified and addressed valid vulnerabilities reported by domestic white-hat hackers through its own vulnerability management system and KISA's cyber security vulnerability information portal. It is also participating in a pilot project for the "Coordinated Vulnerability Disclosure and Vulnerability Disclosure Program (CVD·VDP)" system hosted by the Ministry of Science and ICT and KISA, and in the public-interest AI security initiative "Project Canopy".

LG Uplus will operate the HackerOne programme separately while maintaining its existing joint domestic bug bounty operating framework with KISA.

Hong Kwan-hee (홍관희), head of LG Uplus' Information Security Center and chief information security officer, said the goal was to take pre-emptive action even on vulnerabilities it had not yet discovered as telecoms services increasingly touch overseas infrastructure. He said the company would take the lead in building a safe and transparent security ecosystem and spreading a culture of responsible vulnerability management.

Keyword

#LG Uplus #HackerOne #KISA #Ministry of Science and ICT #Project Canopy
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.