HabrJuly 22, 2026🇷🇺Translated from Russian

Rent, Don't Build: Penetration Testing, Vulnerability Management, and Bug Bounty as a Service

The fifth part of the practical series “Vulnerability Management for Beginners” examines three service-based models that let organizations outsource key tasks instead of building everything in-house: pentest as a service, VM as a service, and bug bounty programs.

Pentest as a Service

Penetration testing simulates an attacker’s attempt to find weaknesses that allow unauthorized actions. Most external pentests follow a black-box approach where testers receive no credentials and must discover entry points the way a real adversary would. Automated scanners rapidly check thousands of hosts for known vulnerabilities, open ports, and version fingerprints, while human teams with certifications such as OSCP combine findings into multi-step attack chains that tools rarely detect.

Automated pentest-as-a-service offerings let companies quickly scan internet-facing assets without deploying their own infrastructure. Customers simply provide IP ranges or domains and prove ownership through domain-registration certificates or signed authorization letters. The provider’s scanners run from external servers and deliver structured reports or API data that can be imported into internal vulnerability-management systems. Limitations include reduced configuration flexibility and the inherent sensitivity of vulnerability data, which must be protected as confidential information.

Market figures show strong growth: the global pentest-as-a-service market reached approximately $1.6 billion in 2024 and continues to expand at roughly 20 percent annually. In Russia the segment also grew by tens of percent in 2025, with several large vendors dominating corporate projects. Tools such as the Russian PT Dephaze platform now provide controlled automated testing that mimics attacker behavior safely.

VM as a Service

Vulnerability Management as a Service extends beyond black-box perimeter scanning by deploying agents or establishing tunnels that allow authenticated, white-box scans of internal assets. This approach produces far more accurate inventories of installed software versions and reduces both missed vulnerabilities and false positives. Results are delivered as reports or API feeds, yet organizations must still maintain internal processes with IT teams to remediate findings within agreed SLAs.

Service customers can define asset criticality, set remediation deadlines, and integrate outputs with patch-management platforms such as Microsoft SCCM or its Russian equivalents. Benefits include rapid deployment, continuous scanner updates handled by the provider, and access to benchmarking data that compares an organization’s remediation speed against industry peers. Risks involve potential data leakage and the need to treat tunnels to internal agents as part of the attack surface.

Prioritization can leverage modern metrics including the fourth version of EPSS, the CISA KEV catalog that now exceeds 1,500 actively exploited vulnerabilities, and the updated FSTEC methodology released on 30 June 2025, which combines CVSS 3.1 base scores with exploit availability and consequence categories.

Bug Bounty Programs

Bug bounty programs invite independent security researchers to examine defined assets in exchange for monetary rewards. Platforms such as HackerOne, Bugcrowd, and Synack manage researcher onboarding, triage, and payments, while Russian platforms Standoff Bug Bounty and BI.ZONE Bug Bounty have become major local players.

In 2025 the two leading Russian platforms received nearly 14,000 vulnerability reports and paid out approximately 260 million rubles. Standoff Bug Bounty alone grew its active programs 2.2 times to 233, registered over 32,000 researchers, and recorded a maximum single payout exceeding 4.9 million rubles. BI.ZONE increased payouts by 50 percent to reach 100 million rubles. Government bodies, including the Ministry of Digital Development, have launched multiple rounds of programs covering systems such as Gosuslugi, while regional administrations and major companies including Sberbank have followed suit.

Successful programs begin in private mode with moderate rewards, clearly defined scope, and established triage workflows. Researchers are incentivized to discover high-impact issues that automated scanners miss, creating a realistic simulation of diverse attacker perspectives. Global payouts underscore the model’s maturity: HackerOne alone distributed about $81 million to researchers between mid-2024 and mid-2025, while Google awarded a record $17 million in 2025.

Related articles

HabrVulnerabilities & Exploits

From Hundreds of Alerts to Proven Vulnerabilities: INFERA AI.SafeCode Unifies Seven Scanners into a Single DevSecOps Pipeline

INFERA AI.SafeCode integrates seven distinct security scanners into one continuous analysis platform that automatically validates findings instead of flooding teams with unconfirmed alerts. The solution combines SAST, SCA, Secrets detection, DAST, AI-driven Pentest agents, Code Fuzzing, and API Fuzzing to deliver proof-of-exploit evidence for high-risk issues. By cross-validating results across engines, the platform reduces false positives and provides developers with actionable tasks that include reproduction steps, stack traces, and one-click AutoFix recommendations directly inside IDEs and Git workflows. Special attention is given to AI-generated code from tools such as GitHub Copilot, Cursor, and Claude, ensuring that rapid development does not introduce unvetted vulnerabilities. The system also maps full attack surfaces, tracks reachability from entry points to vulnerable sinks, and supports compliance requirements including FSTEC orders for critical information infrastructure. MLSecOps capabilities extend coverage to machine-learning pipelines, model configurations, and inference APIs. Overall, INFERA shifts AppSec from reactive alert triage to measurable risk management with clear MTTR metrics and SLA tracking.

HispasecVulnerabilities & Exploits

Critical wp2shell Vulnerability Chain Exploited in WordPress for Unauthenticated Remote Code Execution and Webshell Deployment

A critical vulnerability chain dubbed wp2shell is being actively exploited against WordPress Core installations, enabling unauthenticated remote code execution and the installation of persistent webshells. The flaws affect versions 7.0.x prior to 7.0.2, 6.9.x prior to 6.9.5, and the 6.8 branch before 6.8.6, with patches now available. Attackers chain CVE-2026-63030 and CVE-2026-60137 through the WordPress REST API batch processing endpoint and an SQL injection in WP_Query via the author__not_in parameter. Observed campaigns involve mass scanning, user enumeration, attempts to read wp-config.php, and deployment of PHP webshells in wp-content/cache that return fake 404 responses. Administrators are urged to update immediately, audit logs for anomalous REST API requests, inspect for unauthorized admin accounts or plugins, and rotate credentials if wp-config.php exposure is suspected.

BoletimSecVulnerabilities & Exploits

Cybercriminals Exploit Critical SharePoint Vulnerability CVE-2025-53770 for Remote Code Execution

A critical unauthenticated remote code execution flaw in Microsoft SharePoint Server, tracked as CVE-2025-53770 with a CVSS score of 9.8, is being actively exploited in the wild. The vulnerability stems from unsafe deserialization of data sent to on-premises servers and forms part of the ToolShell attack chain alongside CVE-2025-49704 and CVE-2025-49706. Attackers can execute arbitrary commands, install web shells, and steal ASP.NET cryptographic keys to forge authentication tokens and maintain persistence even after patching. The flaw affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, while SharePoint Online in Microsoft 365 remains unaffected. Two related variants, CVE-2025-53770 and CVE-2025-53771, were developed to bypass earlier mitigations. Administrators are urged to apply all available patches immediately, restrict internet exposure of SharePoint, and hunt for suspicious files, processes, and scheduled tasks.

AntiMalwareVulnerabilities & Exploits

Telegram Bug Floods iPhones with Fake Notifications, Causing Severe Overheating and Battery Drain

A persistent bug in the Telegram messaging app has been causing iOS devices to overheat dramatically and rapidly drain their batteries by spamming hundreds of false push notifications in the background. The issue triggers constant English-language alerts reading "You have a new message" even when users have Russian language settings enabled and message previews turned off, rendering the notifications useless. Reports of the problem first emerged in May but intensified after the release of Telegram version 12.9, which appears to create an infinite loop in background processes that overworks the CPU. Affected users report battery losses of up to 11 percent within 30 minutes of idle time, with some devices becoming hot enough that Apple automatically pauses charging until temperatures drop. One journalist resorted to using a gaming controller with a built-in fan to keep an iPhone cool enough to charge. The only temporary workaround involves clearing the app cache and performing a full reinstall from the App Store, though the bug has been known to return after one or two weeks for some users.