Zoom offered $1.8 million in rewards to researchers who participated in the company's bug bounty program and submitted bug reports in 2021.

Bug bounty programs, whether private (specific security researchers participate) or public (anyone can submit a vulnerability report), have helped many organizations improve their security.
The industry is plagued by talent shortages. Estimates show that there will be approximately 3.5 million job openings by 2025 in the US alone, and until more specialists are available, companies cannot rely solely on internal security teams.
See also: Zoom makes it easy to livestream a meeting on Twitch
This is where bug bounty programs can help: external researchers and bug hunters perform checks and tests on software and services, report security vulnerabilities, and receive rewards for this assistance.
Zoom is an extremely popular video conferencing platform. Its popularity skyrocketed during the lockdowns, as many people were forced to continue working from home and needed to stay in touch with their colleagues. However, various security issues that needed to be addressed. So, Zoom decided to take action and launch a bug bounty program to improve its security posture.
Zoom's main bug bounty program is private, but the platform actively recruits security researchers. Over 800 researchers are participating in the program, which is hosted by HackerOne.
In 2021, the company gave out over $1.8 million to researchers for 401 bug reports. Since the program began, over $2.4 million has been offered.
See also: Zoom live avatars: Appear in meetings as a rabbit or a dog
The company has increased rewards, offering up to $50,000 per report for the most serious vulnerabilities and $250 for less serious bugs.

The company also launched a public Vulnerability Disclosure Program (VDP) that allows anyone, not just established security researchers, to submit vulnerability reports to Zoom. Finally, in recent months, it has also launched a VIP bug bounty program that focuses on licensed versions of Zoom solutions and has expanded the scope of security testing.
"While Zoom tests our solutions and infrastructure daily, we know it's important to extend that testing by utilizing the ethical hacking community to help identify vulnerabilities," Zoom commented.
See also: Bug Bounty 2021: Google paid security researchers $8.7 million
“Secure communication is a top priority for Zoom. The confidentiality and integrity of messages and meetings, as well as the availability and reliability of our global infrastructure, are the primary focuses for hundreds of internal security engineers,” the company says.
For more details click here.
A few words about bug bounty programs
Bug Bounty programs offer sums of money so that security researchers from different parts of the world can discover and report vulnerabilities and weaknesses they find in a company's systems before they are discovered and exploited by malicious users.
Essentially, a bug bounty is a monetary reward given to so-called “ethical hackers” to use their knowledge and skills to protect an organization. The idea is very clever, since in reality, companies use hackers to deal with other hackers.
Source: ZDNet
