October Bonuses Target Copilot and Spark Bug Reports
GitHub is marking Cybersecurity Awareness Month by widening the incentives on its Bug Bounty program and putting a spotlight on some of the researchers who contribute to it. During October 2025, valid vulnerability submissions tied to three newer product areas will earn an additional 10% bonus on top of the usual reward.
The bonus applies to reports involving:
- Copilot Coding Agent
- GitHub Spark
- Copilot Spaces
To qualify, the submission must clearly state how the vulnerability relates to one of those features. The offer is valid for reports submitted between October 1 and October 31, 2025.
Spotlight on Program Contributors
Alongside the boosted payouts, GitHub continues its tradition of profiling the people who report bugs. The company has published a series of interviews with active researchers, covering their approaches, interests and paths into security work. Past spotlights have featured researchers including @chen-robert, @ginkoid, @yvvdwf, @ahacker1, @inspector-ambitious, @Ammar Askar, @adrianoapj and @imrerad. Additional profiles are expected throughout the month.
Events and Program Details
GitHub is also co-hosting the 2025 Glass Firewall Conference: Breaking Bytes and Barriers with Capital One, Salesforce and HackerOne. The event is aimed at women interested in security research and ethical hacking, offering a supportive environment for exploring the field and gaining foundational knowledge. Those interested can find more details and RSVP through the event page.
Full details on the Bug Bounty program, including scope, rules and rewards, are available on the GitHub Bug Bounty website.



