Home / Companies / Bugcrowd / Blog / December 2016

December 2016 Summaries

7 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
Today we are announcing our October and November winners: gtr and Penrose for their winning submissions! Our October and November winner submission challenges encouraged participants to test against thick client applications, including Avira, LastPass, Sophos, and more. To participate in this promotion, one simply needs to review the list of target programs, find a bug, and submit it before December 31st, 2016. The Bugcrowd team has put together resources for new participants to improve their skills, such as Hacking - the Art of Exploitation and Embedded Security CTF. Participants can reach out with additional questions and look forward to the next researcher promotion in coming weeks.
Dec 29, 2016 184 words in the original blog post.
The appsec industry has experienced a record-breaking year with numerous breaches, including the largest breach in history at Yahoo and the largest DDoS attack on record at 1.2TB using Mirai. The bug bounty model has seen significant growth, with many companies adopting it to improve their appsec programs. To support this growth, companies have focused on transparency, education, and quality, providing market rates for bugs, vulnerability rating taxonomies, and training resources to promote clear communication between hackers and companies. The industry has also seen a shift towards conventional wisdom, with the bug bounty economy maturing and stabilizing, driven by the growth of skilled hackers, high-quality results, and successful programs.
Dec 20, 2016 928 words in the original blog post.
Application security spending is at an all-time high, yet attackers continue to breach organizations due to complex attack surfaces and inadequate defenses. The use of connected devices, known as IoTs, has introduced new security risks that must be addressed by CISOs. Pen testing is becoming more effective with crowdsourced testing, which provides a results-based approach to vulnerability identification. Senior development leaders are embracing crowdsourced vulnerability testing as part of the Software Development Life Cycle (SDLC). Social engineering, AI, and machine learning will continue to impact security planning, but human judgment remains crucial in mitigating risks. Finally, bug bounty programs will become more mainstream and integrated into development teams. Overall, 2017 promises to be a challenging year for security professionals as breaches will increase, organizations will focus on reducing business impact, consumers will demand improved device security, and regulation will become even more prevalent.
Dec 14, 2016 1,059 words in the original blog post.
Setting up a successful bug bounty program requires careful consideration of various aspects, including access provisioning. The goal is to create a frictionless experience for researchers while minimizing challenges for internal teams. This involves providing multiple credentials for each user level, considering testing restrictions, and offering supplemental information such as API documentation and setup guides. Additionally, it's essential to ensure the test environment can handle concurrent testers and avoid sensitive functionalities that could impact other elements of the organization. By following best practices, such as not sharing credentials and providing researchers with necessary tools, organizations can increase their program's success and visibility.
Dec 12, 2016 1,075 words in the original blog post.
We’re excited to announce today that Crowdcontrol now offers a more streamlined process to sign up for an alternative payout option, Payoneer. We’ve heard many requests from researchers that they’d like an alternative to PayPal, and we’re happy to provide an option for those researchers. Payoneer provides an alternative means for researchers to receive bounty payments either through a prepaid MasterCard card or a direct bank transfer. Researchers can now easily sign up with Payoneer by going to their profile settings, registering with Payoneer, and choosing their preferred payment method. It’s recommended that researchers sign up with multiple payout methods due to the variety of programs available on Crowdcontrol. Once signed up, researchers can update their preferred payout method at any time.
Dec 09, 2016 293 words in the original blog post.
Bugcrowd has announced its November 2016 Hall of Fame winners, recognizing top performers zseano, mert, and ansariosama for their hard work. The researchers will receive bonuses for their performance, with zseano taking the top spot with 699 points worth $2,500, followed by mert with 603 points worth $1,500 and ansariosama with 580 points worth $1,000. To excel in Bugcrowd, researchers must identify high-severity bugs that result in critical security impacts, as these earn the most kudos points. Submitting such bugs not only earns bigger rewards but also increases the chances of being invited to private bounty programs. The company looks forward to announcing the December Hall of Fame results.
Dec 07, 2016 211 words in the original blog post.
After over two years of running an outstanding bug bounty program with Bugcrowd, we'd like to give some recognition to one of our longest standing and committed customers--Aruba Networks. Since 2014, Aruba has successfully leveraged Bugcrowd's most skilled and trusted researchers through a private bug bounty program for their web applications and hardware devices. As Aruba scaled their operations, they prioritized product and application security, bringing on an all-star security team, multiple third-party testing engagements, and hiring independent security researchers to freelance. They turned to Bugcrowd to augment their existing efforts with a more focused private bug bounty program that allowed them to tailor their testing pool based on specific skill sets, have direct communication with a smaller group of testers, and harness the power of a public bug bounty program while retaining control. With this approach, Aruba has positioned themselves as thought leaders in application security, gained traction in their program, and seen high-quality findings from researchers. Their private bug bounty program has retained astounding traction over two years, receiving over 500 submissions from researchers around the world, and serving as a great model for others looking to implement a bug bounty program.
Dec 01, 2016 549 words in the original blog post.