Prior to the launch of the bug bounty challenge, students were equipped with training from HackerOne’s web security training platform, Hacker101.
“By allowing our students to hack our own applications, we are breaking conventional and conservative notions, and offering students the unique experience of hacking on production systems,” says Tommy Hor, chief information technology officer at NUS. “It is not possible to be ‘100 percent safe’ in cybersecurity. Therefore, we adopt a proactive and predictive approach to cybersecurity and the bug bounty challenge is a great example of this. In this case, participating students are given the opportunity to search for vulnerabilities in the systems and applications they are already familiar with because of regular usage. This complements the regular vulnerability scanning and penetration testing performed by our staff. Collectively, these efforts help us to identify and remediate security vulnerabilities before they can be exploited by malicious threat actors.”
“The bug bounty program provides a great opportunity for us to put our technical skills to the test to find bugs in high-value web applications,” said Ngo Wei Ling, a Year 2 undergraduate from NUS School of Computing who participated and won a bounty.
Another winner, Ahn Tae Gyu, a Year 3 undergraduate from NUS School of Computing, adds, “We carried out reconnaissance and active enumeration, which enabled us to uncover vulnerable systems and web pages, in which we were able to discover hidden security bugs. This process provided us with the understanding of how web servers in production mode are configured and it is commendable that NUS is aiming to resolve security bugs before malicious attackers are able to exploit them by fostering responsible disclosure.”
Competitions for student hackers are becoming more commonplace as institutions, companies, and educators strive to give students all the skills they’ll need to tackle cybersecurity.
The National Cyber League (NCL) is a biannual cybersecurity competition for high school and college students. The competition consists of a series of challenges that allows students to demonstrate their ability to identify hackers from forensic data, break into vulnerable websites, recover from ransomware attacks, and more. Students compete in the NCL to build their skills, obtain scouting reports of their performance for hiring purposes, and to represent their school.
The Cyberlympics is a competition aimed at a broad scope of IT security professionals. It enforces the idea of teamwork by providing challenges that span nearly all areas of IT security, such as pen testing, forensics, malware, log analysis, system exploitation, and physical security. Cyberlympics is not solely focused on offense or defense but rather, it’s an all-encompassing approach allowing teams to compete with whatever cybersecurity strengths they bring to the competition.
The CSAW games, founded in 2003 as a small contest by and for NYU Tandon students, have grown to become a comprehensive set of challenges by and for students around the globe. NYU students continue to design the contests under the mentorship of information security professionals and faculty. NYU Tandon’s student-led Offensive Security, Incident Response and Internet Security (OSIRIS) laboratory, home to weekly student-led Hack Night training and student research, leads the Red Team and CTF challenges.
The U.S. Cyber Challenge (USCC) aims to significantly reduce the shortage in today’s cyber workforce by serving as the premier program to identify, attract, recruit and place the next generation of cybersecurity professionals. USCC’s goal is to find 10,000 of America’s best and brightest to fill the ranks of cybersecurity professionals where their skills can be of the greatest value to the nation. USCC works with the cybersecurity community to bring accessible, compelling programs that motivate students and professionals to pursue education, development, and career opportunities in cybersecurity.
- Weak tech could push students, faculty to other institutions - April 13, 2026
- 13 predictions about edtech, innovation, and–yes–AI in 2026 - January 1, 2026
- 5 essential dimensions of AI literacy - December 12, 2025
