Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Department of Defense officially launches ‘Hack the Pentagon’ program

Add as a preferred source on Google

The Pentagon wants hackers to put its websites’ cyber defenses to the test with its bug bounty “Hack the Pentagon” program. And Hack The Pentagon is now officially up and running, with a $150,000 bounty budget. Don’t just start hacking, though: in order for that to not be a felony, you need to sign up with HackerOne.

Vetted hackers will be invited to test the security of the Department of Defense website. The program, set up by the Pentagon’s Defense Digital Service (DDS), is focused on the public-facing sites and, at least for now, won’t include the testing of more private systems and networks that may contain sensitive data or details on weapons.

Recommended Videos

Bug bounty programs are pretty common. They’re used by companies like Google and Facebook as well as startups to encourage white-hat hackers to privately disclose vulnerabilities they find in their sites and services in return for a reward, usually cash.

Hack the Pentagon, which launches in April, is the first such program designed by the federal government and is modeled on these traditional bug bounty schemes. The details of the program are still being finalized and the prizes “could involve monetary awards” reports Reuters, but this has yet to be confirmed.

The Pentagon previously conducted such tests internally but the Department of Defense says it is expecting thousands of applicants. White-hat hackers who are interested must pass a background check before they can start testing the sites.

“I am confident that this innovative initiative will strengthen our digital defenses and ultimately enhance our national security,” said Defense Secretary Ashton Carter. Chris Lynch, head of DDS, added that “Bringing in the best talent, technology, and processes from the private sector … helps us deliver comprehensive, more secure solutions to the DOD.”

The Pentagon and several government departments are probably having a serious rethink of their cyber defense strategy following a pretty rocky couple of years that saw the Office of Personnel Management hacked, and most recently, the IRS breached by a cyberattack.

Interested parties can sign up with Hacker One, a security firm that specializes in hiring hackers to reveal vulnerabilities. Ars Technica is reporting a $150,000 bounty budget for the project, so finding a flaw could prove valuable.

Anyone legally permitted to work in the US can apply, pending a background check. The full details:

  • You must have successfully registered as a participant through this security page.
  • You must have a U.S. taxpayer identification number and a social security number or an employee identification number and the ability to complete required verification forms.
  • You must be eligible to work within the U.S.; meaning you are a U.S. citizen, a noncitizen national of the U.S., a lawful permanent resident, or an alien authorized to work within the U.S.
  • You must not reside in a country currently under U.S. trade sanctions.
  • You must not be on the U.S. Department of the Treasury’s Specially Designated Nationals list.

One more exception: Current members of the U.S. Military are not permitted to participate, with one exception: United States Digital Service personnel with express approval from their supervisors.

If all this applies to you, and you’ve got some skills, sign up and see what you can do!

Jonathan Keane
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
MelGeek MADE84 Ultra Review: Getting addicted to this magnetic keyboard was only a matter of time
I tried my first Hall Effect keyboard, and now my brown switches are just gathering dust
Computer, Computer Hardware, Computer Keyboard

Mechanical keyboards are one of those rabbit holes I’ve always been happy to fall into. I spend most of my day writing, then somehow end up using the same keyboard for several more hours once I start gaming. Naturally, how a keyboard responds and sounds are important to me. But more often than not, I found myself relying on this dusty old mechanical keyboard with brown switches. Something about the brown switches and construction always made it feel natural to me. All of this changed after I tried the MelGeek MADE84 Ultra V2 for a review.

This keyboard instantly caught my attention with its transparent keycaps, massive light bar, aluminum body, and lighting running around almost every side, which immediately gives it away as a gaming keyboard. It's not being subtle about it at all. After about two weeks of using it for work and games, the styling is just one of the things it has going for it.

Read more
AI agents are already breaking the rules in cyber tests. OpenAI’s answer is a more capable one
GPT-5.6-Cyber trades some safeguards for stronger defensive capabilities, but access is tightly restricted
A dark mystery hand typing on a laptop computer at night.

OpenAI has built a cybersecurity model specifically for advanced requests that its standard models often refuse. GPT-5.6-Cyber is available through the restricted Daybreak Red program and is meant for work such as exploit development and advanced security research.

The capability jump is hard to miss. OpenAI says GPT-5.6-Cyber completes 95% of requests in its internal Advanced Cybersecurity Completion Rate evaluation. Regular GPT-5.6 Sol completed just 1.5%. That leap comes after several cyber evaluations showed AI agents wandering beyond the boundaries researchers had set for them.

Read more
Meta’s new AI model runs entirely offline, but your GPU needs to keep up
Meta drops a free 30 billion parameter AI model that lives entirely on your desktop.
meta-logo

Meta has a new AI model out, and for once, the biggest headline isn't about capability; it's about freedom. Muse Glimmer, sitting around 30 billion parameters, ships with an Apache 2.0 license, meaning the weights on Hugging Face are yours to download, modify, and build on top of, no permission needed. You can simply run it on a graphics card on your local machine, no server farm or online connectivity required. 

Meta's Superintelligence Lab took its larger Muse Spark and essentially had it teach a smaller, leaner version to think as it does. Muse Glimmer accepts both text and image inputs, though it only answers in text. It supports over 100 languages, remembers conversations stretching past 131,000 tokens, and its knowledge stops at January 4, 2026.

Read more