Security platform HackerOne has today released its 2021 Hacker Report showing an increase in submitted vulnerability reports last year.
According to the survey of 4000 global hackers, carried out between December 2020 and January 2021, there has been a 63% increase in the number of researchers submitting reports across 20 different vulnerability categories; an increase of 143% since 2018.
The report also revealed that more than one-third (38%) of hackers spent more time operating since the Covid-19 pandemic started, with a 53% rise in submissions for both Improper Access Control and Privilege Escalation.
Commenting on the report, HackerOne co-founder Jobert Abma said: “This year’s Hacker Report demonstrates the depth of vulnerability insights that hackers bring to a security program.
“We’re seeing huge growth in vulnerability submissions across all categories and an increase in hackers specialising across a wider variety of technologies.
“As we see slower growth in some common vulnerabilities that are easily found and fixed, we’re seeing hackers be more creative in their attempt to discover new attack vectors.
“Every time a hacker links several low-severity vulnerabilities together to help a customer avoid a breach, or finds a unique bypass to a software patch, it proves that machines will never truly outpace humankind.”
Ethical hacking has fast become a multi-million-dollar industry, with companies around the world now seeing the value of fighting cybercrime before it can affect their business.
The latest report highlights the importance of ethical hacking to catch cyber-threats. There has been a boost in cybersecurity incidents over the last year as hackers exploit the Covid-19 pandemic for financial gain.
Due to the digital transformation brought on by the pandemic, ethical hackers have “adapted and zeroed in” on emerging threats. Reports for vulnerabilities caused by trends like moving to the cloud have proliferated in the past year, with misconfiguration vulnerabilities rising by 310%.
Recommended
- Scotland 5G Centre’s new toolkit to speed up mast installation
- Ready the Red Team! SBRC’s Declan Doyle explains ethical hacking
- International Women’s Day | Q&A with SDS’s Digital Skills Team
Last week, a communication and IT vendor for 90% of the world’s airlines was the target of a cyber-attack that compromised passenger data stored on the company’s US servers.
Malaysia Air and Singapore Airlines alerted their customers that they have been compromised as part of the breach, highlighting the scope that a cyberattack can have.
Similarly, the recent Blackbaud attack affected hundreds of companies globally, including the National Trust, Edinburgh Zoo and codebreaking museum Bletchley Park.
It was initially believed that no financial data had been stolen in the attack. However, the company later admitted that financial details and passwords for thousands of people were among data feared stolen.
The fight against cybercrime is lucrative for ethical hackers, or White Hat hackers, who earned over $40 million in bounties last year, bringing total hacker earnings to date over $100 million.
In addition to bounties, learning continues to be a top driver for hackers, with 85% doing it to learn, 62% doing it to advance their career and 33% already having leveraged their skills to secure a job.





