A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug Bounty hunters.
- 123Contact Form
- 99designs
- Abacus
- Acquia
- ActiveCampaign
- ActiveProspect
- Adobe
- AeroFS
- Airbitz
- Airbnb
- Algolia
- Altervista
- Amara
- Amazon Web Services
- Amazon.com
- ANCILE Solutions Inc.
- Anghami
- ANXBTC
- Apache httpd
- Appcelerator
- Apple
- Apptentive
- Aptible
- Ardour
- ARM mbed
- Asana
- ASP4all
- AT&T
- Atlassian
- Attack-Secure
- Authy
- Automattic
- Avast!
- Avira
- AwardWallet
- Badoo
- Barracuda
- Basecamp
- Beanstalk
- BillGuard
- Billys Billing
- Binary.com
- Binary.com Cashier
- BitBandit.eu
- Bitcasa
- BitCasino
- BitGo
- BitHealth
- BitHunt
- BitMEX
- Bitoasis
- Bitpagos
- Bitrated
- Bitreserve
- Bitspark
- Bitwage
- BitWall
- BitYes
- BlackBerry
- Blackboard
- Blackphone
- Blesta
- Block.io
- Block.io, Inc.
- Blockchain.info
- BlockScore
- Bookfresh
- Box
- Braintree
- BTC_sx
- Buffer
- BX.in.th
- C2FO
- Campaign Monitor
- CARD.com
- Catchafire
- Caviar
- CCBill
- CERT/CC
- Certly
- ChainPay
- ChangeTip
- Chargify
- Chromium Project
- Circle
- CircleCI
- Cisco
- Clojars
- CloudFlare
- Cobalt
- Code Climate
- CodeIgniter
- CodePen
- Coin Republic
- Coin.Space
- Coinage
- Coinbase
- CoinDaddy
- Coinkite
- Coinport
- coins.ph
- Cointrader.net
- Coinvoy
- Compose
- concrete5
- Constant Contact
- Counterparty
- Coupa
- Coursera
- cPanel
- cPaperless
- Crix.io
- CrowdShield
- Cryptocat
- Cupcake
- CustomerInsight
- Cylance
- Dato Capital
- Detectify
- DigitalOcean
- DigitalSellz
- Django
- Doorkeeper
- DoSomething
- DPD
- Dropbox
- Dropbox Acquisitions
- Drupal
- eBay
- Eclipse
- EMC
- Enano
- Engine Yard
- Envoy
- Eobot
- EthnoHub
- Etsy
- EVE
- Event Espresso
- Evernote
- Expatistan
- ExpressionEngine
- Ezbob
- Faceless
- Factlink
- FanFootage
- FastSlots
- Flash
- Flood
- Flow Dock
- Flox
- Fluxiom
- Fog Creek
- FormAssembly
- Founder Bliss
- Foursquare
- Freelancer
- Gallery
- Gamma
- Gemfury
- General Motors
- GhostMail
- GiftCards.com
- GitHub
- GitLab
- GlassWire
- Gliph
- GlobaLeaks
- Google PRP
- Google VRP
- Gratipay
- GreenAddress
- Greenhouse.io
- Grok Learning
- HackerOne
- Harmony
- Heroku
- Hex-Rays
- Hive Wallet
- Hootsuite
- HTC
- Huawei
- Hubdia
- Humble Bundle
- Ian Dunn
- IBM
- ICEcoder
- Iconfinder
- Ifixit
- Imgur
- ImpressPages
- Indeed
- Independent Reserve
- Informatica
- IntegraXor
- Internetwache
- InVision
- IRCCloud
- itBit Exchange
- ITRP
- joola.io
- Joomla
- JRuby
- jsDelivr
- Juniper
- Kadira
- Kaneva
- Kayako
- Kenna
- Keybase
- Khan Academy
- Kraken
- Lancor Income
- LastPass
- LaunchKey
- Lean Testing
- leetfiles
- Librato
- LibSass
- Liferay
- LiveEnsure
- LocalBitcoins
- Localize
- Logentries
- Lookout
- Magento
- MAGIX
- Mahara
- MaiCoin
- Mail.Ru
- Mailbird
- MailChimp
- ManageBGL
- ManageWP
- MapLogin
- Marktplatts
- Mavenlink
- Maximum
- MCProHosting
- MEGA
- Mercury
- Meteor
- meXBT
- Microsoft
- Mimecast
- Mobile Vikings
- Modus CSR
- MoneyBird
- MoneyStream
- Moodle
- Motorola Solutions
- Mozilla
- mynxt.info
- Natures Organics
- NCSC
- Nearby Live
- Nest
- Netflix
- Nexmo
- Nginx
- Nitrous
- Nokia Networks
- NoPass
- NZRS
- Offensive Security
- ok.ru
- OKCoin
- OkCupid
- Olark
- Opal Cryptocurrency
- Openfolio
- OpenSSL
- OpenStack
- OpenText
- Opera
- Optimizely
- Oracle
- ownCloud
- PagerDuty
- Pantheon
- Panzura
- Paragon Initiative Enterprises
- Paychoice
- PayMill
- PayPal
- Perl
- Phabricator
- PHP
- Pidgin
- PikaPay
- PinoyHackNews
- Piwik Open Source Analytics
- Plone
- Poloniex
- Postmark
- Prezi
- Projectplace
- PullReview
- Puppet labs
- PureVPN
- Python
- QIWI
- Quadriga CX
- QuickBT
- Rackspace
- Rdbhost_service
- Red Hat
- Relaso
- RelateIQ
- Release Wire
- Respondly
- Revive Adserver
- Ribose
- Ripio
- Ripple
- Riskalyze
- Romit
- Ruby
- Ruby on Rails
- Salesforce
- Samsung TV
- Sandbox Escape
- SAP
- Schuberg Philis
- Scorpion Software
- Secret
- Secure Works
- Sellfy
- ServiceRocket
- ShareLaTeX
- Sherpany
- Shopify
- Sifter
- Silent Circle
- Simple
- SiteGround
- Skoodat
- Skrill
- Slack
- Snapchat
- Snappy
- Sonatype
- Sony
- SoundCloud
- SpectroCoin
- Spendbitcoins
- SplashID
- Splitwise
- Spotify
- Sprout Social
- Square
- Square Open Source
- StatusPage
- StopTheHacker
- Subledger
- Subrosa
- Sucuri
- Symantec
- Tagged
- Taptalk
- Tarsnap
- TeamUnify
- Tele2
- Telekom
- The Internet
- The Mastercoin Foundation
- ThisData
- TimeTrex
- ToyTalk
- Trello
- Tuenti
- Twilio
- Twitch
- Uber
- Ubiquiti Networks
- Unitag
- Urban Dictionary
- Uzbey
- Valve Software
- VCE
- Venmo
- Version Cake
- Viadeo
- Vimeo
- VK.com
- Volusion
- VPNSox
- vulners.com
- Webconverger
- Websecurify
- Weebly
- WePay
- Whisper
- WHMCS
- Windthorst ISD
- withinsecurity
- WizeHive
- WordPoints
- Wordware
- WP API
- Xen Project
- Xmarks
- Yahoo
- Yandex
- Yanomo
- Yesware
- Zapier
- Zaption
- ZenCash
- Zendesk
- Zetetic
- Ziggo
- Zimbra
- Zomato
- Zopim
- Zynga
- http://sakurity.com/blog - by Egor Homakov
- http://respectxss.blogspot.in/ - by Ashar Javed
- http://labs.detectify.com/ - by Frans Rosén
- https://www.cliffordtrigo.info/ - by Clifford Trigo
- http://stephensclafani.com/ - by Stephen Sclafani
- http://sasi2103.blogspot.co.il/ - by [Sasi Levi] (https://twitter.com/sasi2103)
- http://www.pwnsecurity.net/ - by [Shashank] (https://twitter.com/cyberboyIndia)
- https://www.breaksec.com/ - by [Nir Goldshlager] (https://twitter.com/Nirgoldshlager)
- http://pwndizzle.blogspot.in/ - by [Alex Davies] (https://twitter.com/pwndizzle)
- http://c0rni3sm.blogspot.in/ - by [yappare] (https://twitter.com/yappare)
- http://exploit.co.il/blog/ - by Shai rod
- http://www.riyazwalikar.com/ - by Riyaz Ahemed Walikar
- http://panchocosil.blogspot.in/ - by Francisco Correa
- http://breakingmesh.blogspot.in/ - by Sahil Sehgal
- http://www.websecresearch.com/ - by Ajay Singh Negi
- http://www.securitylearn.net/about/ - by Satish Bommisetty
- http://www.secinfinity.net/ - by Prakash Sharma
- http://www.websecuritylog.com/ - by jitendra jaiswal
Your contributions are always welcome!