Bug bounty programs allowed the US agency to receive 2,837 valid bug reports from 650 white hat hackers located in 50 countries around the world. HackerOne and DoD have run bug bounty challenges for Hack the Pentagon, Hack the Army and Hack the Air Force. The hackers have earned over $300,000 in bounties for their contributions, they reported nearly 500 vulnerabilities in nearly 40 DoD components, more than 100 of the flaws have been rated critical or high severity. The list of vulnerabilities includes remote code execution, SQL injection, and authentication bypass issues.”]
Source: https://securityaffairs.co/wordpress/65491/hacking/bug-bounty-program-pentagon.html