What happened
GitHub announced that starting July 27, 2026, public bug bounty payouts will be cut by at least half across all severity tiers, with critical vulnerability rewards dropping to a flat $10,000 — down from a previous range of $20,000 to over $30,000. Researchers who want higher compensation will need an invitation to GitHub's permanent VIP program, which retains the $30,000-plus ceiling. Reports already submitted or sitting in GitHub's triage queue before the cutoff date will be honored under the original payout terms. Separately, LG Electronics USA announced plans to suspend smart TV apps on its webOS platform that secretly enroll televisions as residential proxy nodes, routing third-party internet traffic through consumers' home connections without their knowledge.
Why it matters for your business
For security teams that rely on external researchers to surface vulnerabilities in GitHub-hosted code or CI/CD pipelines, the restructuring effectively concentrates top-tier threat intelligence inside a closed researcher pool, reducing the breadth of public scrutiny on the platform. Organizations with developer workflows deeply tied to GitHub should evaluate whether their own internal bug bounty or responsible disclosure programs similarly funnel talent away from open participation. On the LG front, the discovery that over 42 percent of apps on the webOS store were enabling unauthorized proxy behavior is a stark reminder that smart devices on corporate or home-office networks can become silent traffic relay points. Security operations teams should audit what IoT and smart appliances are connected to their networks and ensure firmware and app permissions are reviewed regularly.
What to watch next
Observers will be tracking whether other major platforms follow GitHub's lead in tiering bounty programs, which could dampen independent security research and reduce vulnerability reporting volume industrywide. On the smart TV front, LG's enforcement timeline and the extent to which identified apps are actually removed — rather than merely updated — will determine how meaningful the policy change proves in practice. Regulatory scrutiny around undisclosed proxy enrollment in consumer devices is also a developing area, particularly in the EU under the Cyber Resilience Act framework.
