Home / Companies / Bugcrowd / Blog / November 2016

November 2016 Summaries

6 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
We launched Bugcrowd's first bounty program four years ago yesterday, initially with a time-boxed, open program with cash rewards, later expanding to a public program with continuous testing and increasing rewards up to $5,000. We've also run multiple private On-Demand Programs on Crowdcontrol, focused penetration tests with researcher pools. Our bug bounty community has contributed significantly to our product's security and development, helping us build a more powerful and intuitive product.
Nov 21, 2016 324 words in the original blog post.
Barracuda Networks has launched its Security Bug Bounty Program six years ago, which has received a tremendous response from the research community and provided valuable contributions to the security of their products. The program represents a significant way for security vendors to promote collaboration and reward researchers for their work while encouraging responsible disclosure. As the threat environment continues to evolve, Barracuda is expanding its Security Bug Bounty Program to include its cloud services, making it by invitation only, with additional details to be released in early December. The existing program will continue but with limited bounty awards for specific vulnerabilities, and all submissions will receive Kudos points that contribute to a leaderboard bonus program. The program's success is attributed to the contributions of researchers who have made substantial contributions to Barracuda's security products.
Nov 17, 2016 435 words in the original blog post.
Okta, a leading provider of identity for the enterprise, is launching its first public bug bounty program after running an extensive private program with Bugcrowd, to augment its robust security team and strategy and further enhance product security. The company has prioritized customer success, which translates directly to customer security and assurance, and has shown strong commitment to security research through its private program. With the transition to a public program, Okta will now leverage the full extent and resources of Bugcrowd's curated crowd to focus internal resources on critical early stages of product design and development, enabling improved response time and increased transparency. The program aims to reward vulnerabilities up to $15,000 per discovery, with a disclosure policy requiring explicit permission for public disclosure.
Nov 16, 2016 367 words in the original blog post.
InVision has launched a public bug bounty program as part of its best-in-class security strategy, utilizing the diversity and volume of a crowd-sourced approach to bolster product security in an increasingly complex threat environment. The company's robust internal security efforts and high-caliber external security assessments are complemented by the bug bounty program, which leverages a large and diverse community of researchers to identify vulnerabilities. With rewards up to $1500 per vulnerability and a focus on customer security, InVision is taking a proactive approach to protecting its users' data and applications.
Nov 09, 2016 244 words in the original blog post.
Bugcrowd has announced the winners of its Hall of Fame awards for September and October 2016, with three researchers tied for first place due to an unusual situation where duplicate vulnerability reports affected leaderboard points. The top performers in each month received bonuses for their hard work, and Bugcrowd has made changes to its code to prevent similar situations from happening again. The company invites researchers to submit high-severity bugs that result in critical security impact to earn more kudos points and potentially get invited to private bounty programs.
Nov 07, 2016 558 words in the original blog post.
Indeed's bug bounty program has been running since May 2014, leveraging Bugcrowd to tap into the power of the crowd and improve internal and external security testing practices. The program has seen significant growth, with over 3,000 submissions from researchers in 60 countries, fixing nearly 500 valid bugs and paying out over $100,000. Through two years of findings, Indeed has identified trends that have enabled them to evolve and improve their program, including improved average priority, increased payouts, and a decrease in signal-to-noise ratio. The company has demonstrated commitment and success, earning trust and loyalty from top researchers and consistently high activity for a sustained amount of time.
Nov 01, 2016 843 words in the original blog post.