Of course, that puts you in a position of interacting with the US government on security research.
Of course, that puts you in a position of interacting with the US government on security research.
https://www.wired.com/story/hack-the-pentagon-bug-bounty-res...
The bug bounty programs are basically a counteroffer to those.
It's certainly fairly overt, though I don't know the legal standing. Whether or not a researcher broke CFAA in finding a bug, is describing it to a third party a criminal act?
The zero days you refer to would instead be vulnerabilities in software which a researcher would test against local software / hardware they own, not only for legal reasons, but also because actively probing a web server can set off alarm bells (Making access less useful after validation).
Largest exploit type goes for up to $1.5MM: https://zerodium.com/program.html