January 2017 Summaries
17 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Application security organizations are facing a steep disadvantage due to modern attackers, according to industry leaders surveyed at the end of 2016. CISOs and security decision-makers are concerned about application security in 2017, particularly breaking the cycle of being at a disadvantage against adversaries. To get ahead, they need to understand their spending and resource allocation priorities, as well as what the modern-day appsec landscape looks like. The survey aims to provide insights into how CISOs can break this cycle and stay ahead of attackers through interviews with innovative security leaders in the industry.
Jan 31, 2017
151 words in the original blog post.
The world's largest consumer technology show, CES, was attended by millions, with the speakers discussing various emerging technologies such as AR/VR, autonomous cars and sensors, home automation, and wearables. The security implications of these technologies were a major focus, with experts highlighting the need for better protection against attacks, including those related to IoT devices, drones, and sensors. Many vendors were found to be lacking in their approach to security, with some even admitting that they were still in beta stages. However, there were also some standout vendors who prioritized security, and the industry is expected to continue evolving rapidly, creating new opportunities for job seekers and consumers alike.
Jan 30, 2017
1,434 words in the original blog post.
InVision's VP of Information Security, Johnathan Hunt, shares his story on transitioning from self-managed to managed bug bounty programs, highlighting the benefits of improved efficiency, reduced workload, and enhanced security coverage through partnerships with platforms like Bugcrowd. By leveraging a managed program, InVision has been able to streamline their vulnerability assessment process, free up resources for remediation, and align more closely with development cycles, ultimately improving their overall security posture.
Jan 27, 2017
500 words in the original blog post.
Target Management is an update to Bugcrowd's Crowdcontrol platform that allows customers to define targets by attributes such as target type and business impact, with the goal of collecting data to provide improved program feedback and a more intelligent platform. This new approach enables customers to granularly define each target, categorizing it by type and assessing its business impact, which will be used to improve various capabilities including submission workflow, program insights, curated crowd deployment, and suggested payout. The update introduces a Target Repository where organization owners can store targets at the organization level, providing more control over target definition and management.
Jan 27, 2017
432 words in the original blog post.
We saw a nearly doubling of our researcher community in 2016, with a 287% increase in researcher payouts and a 66% increase in average payout size. We launched a program to reward top-performing researchers on an annual basis, with bonuses awarded to those who meet specific criteria, including high submission acceptance rates and qualifying submissions. In 2016, our top 90 researchers earned over half of the total payouts, totaling nearly $2 million, while also receiving bonus cash, with this year's bonus pool being announced as 50% higher at $75,000. We highlight the work of all researchers who participate in our program and provide a leaderboard for tracking progress.
Jan 25, 2017
301 words in the original blog post.
The application security space has grown significantly over the years, with hundreds of vendors and firms contributing to a market estimated to reach $7.6 billion by 2021. The most utilized application security practice is penetration testing, used by over 80% of respondents, followed by incident response teams and processes, and application vulnerability scanning. However, smaller companies tend to utilize fewer activities, with significant variations in the use of static analysis and threat modeling. Despite saturation in many methods, breaches still occur due to hacking. Bug bounty programs have emerged as a solution, leveraging top security researchers to augment automation solutions and find results beyond penetration testing, addressing challenges such as finding vulnerabilities that automated tools may miss.
Jan 23, 2017
368 words in the original blog post.
Twilio has successfully run a public bug bounty program for two and a half years, engaging with security researchers from around the world through various methods, including increasing rewards to boost testing activity. The program has received over 1200 submissions and paid out over $50,000, highlighting Twilio's commitment to product security and their ability to improve their vulnerability finding capabilities while freeing up resources for other areas of the business. Through a collaborative approach with Bugcrowd, Twilio has formed meaningful relationships with top researchers and learned valuable lessons about the effectiveness of crowdsourced testing in enhancing their product security initiatives.
Jan 17, 2017
381 words in the original blog post.
We have extended our thick client software testing promotion until March 2017, increasing the reward pool and offering a total of $2500 cash prizes. The contest allows researchers to submit valid vulnerabilities against thick client targets for a chance to win up to $1500. Interested individuals can start by emailing `[email protected]` to express their interest and learn about online resources to get started, including recommended books and a CTF challenge.
Jan 16, 2017
390 words in the original blog post.
Ongoing coverage of wide-scale ransom attack in progress: How to protect Internet-facing data stores
A new trend of ransom attacks has emerged on the internet, initially affecting MongoDB installations but now expanding to include Elasticsearch clusters and potentially other technologies. Over 34,000 MongoDB databases have been erased, while over 1,600 Elasticsearch instances have been compromised. The most at-risk technologies currently are MongoDB, Elasticsearch, Redis, Cassandra, and Hadoop. To prevent these attacks, users should perform backups of their data, configure authentication on datastores if available, reconfigure environments to isolate datastores from the internet, restrict access via IP white-lists, and conduct immediate adversarial assessment of their internet perimeter.
Jan 15, 2017
329 words in the original blog post.
Crowdcontrol has introduced customizable fields in its vulnerability management platform, allowing program owners to improve their workflow experience by adding specific fields to the submission form. This feature enables customers to align their bug bounty management process with their application security and development workflows, such as assigning teams or specifying affected application versions. The custom fields are designed for program owners only and won't affect visible data already submitted, providing a more granular way to manage submissions. To use this feature, users can navigate to the 'Custom Fields' tab in Program Settings, add new fields, and save details to appear on submission forms.
Jan 13, 2017
176 words in the original blog post.
We surveyed 100 CISOs and decision makers in 2016 to understand their security priorities for 2017, and found that top areas of focus included securing applications hosted in public clouds and public-facing web applications, with mobile applications also being a key area of investment. The current state of the internet's attack surface presents hackers with more opportunities than ever, making it difficult for organizations to keep up with potential exploits, resulting in rising breach rates. Cybersecurity challenges include staffing or resourcing issues, budget constraints, and getting management buy-in on security initiatives, with larger organizations facing unique challenges such as internal buy-in and budgeting. To combat these challenges, traditional application security tools are not sufficient, and organizations need to find new ways to stay ahead of modern-day attackers.
Jan 11, 2017
497 words in the original blog post.
NETGEAR has launched a public bug bounty program with Bugcrowd to improve the security of its products and stay ahead of emerging threats.` The company is committed to protecting user data and privacy by being proactive in its approach to security, adding a managed bug bounty program as part of its efforts.` The scope of the program includes NETGEAR's devices, mobile applications, and exposed APIs, with potential rewards ranging from Bugcrowd points to $15,000 per identified bug.` By participating in the program, security researchers can contribute to enhancing the company's security posture.
Jan 10, 2017
186 words in the original blog post.
Bugcrowd has updated its user permissions in Crowdcontrol, allowing companies to customize their team members' roles for specific programs. This update is important as organizations are running multiple bug bounty programs with different security maturity levels and goals, requiring a more nuanced approach to distributing permissions. The new program-specific roles feature enables organization owners to assign different roles and permissions to team members for each program, such as 'program analyst', 'program viewer', or being excluded from certain programs. Additionally, program administrators can invite team members and manage their teams on specific programs. This update introduces two levels of roles: overarching organization roles and individual program roles, allowing for more granular control over permissions.
Jan 06, 2017
295 words in the original blog post.
Okta's public bug bounty program has significantly enhanced the security of their Identity Cloud by providing a rigorous vulnerability discovery program that utilizes tools like Bugcrowd.
The program offers rewards up to $15,000 and has been shown to be more cost-effective than other testing methods, with continuous testing in earlier phases of design and development allowing for end-to-end security testing.
Okta's commitment to customer security and assurance is a key company value, and their bug bounty program plays a crucial role in supporting their Software Development Lifecycle (SDL) and vulnerability management programs.
Jan 05, 2017
220 words in the original blog post.
Today is the first day of another Consumer Electronics Show–CES, marking 50 years since its launch as a platform for consumer electronics. The scope of CES has expanded significantly over the years to include all aspects of consumer technology, with the majority of products on display being Internet of Things devices or IoT. This explosion in IoT devices has led to major shifts in how we work, play, and live our lives, but also created significant security concerns due to the rapid development pace and widespread adoption by consumers. As a result, most IoT vendors are playing catch-up when it comes to security, with many experts, including myself as Head of Trust and Security at Bugcrowd, sounding the alarm on these vulnerabilities. The show will feature products and discussions on the latest security measures for new IoT devices, with the question lingering whether consumer demand will force vendors to prioritize security or push products to market before they've been fully tested.
Jan 05, 2017
346 words in the original blog post.
Bugcrowd has announced its December 2016 Hall of Fame winners, with mongo taking first place and BAIJU_ABRAHAM and yappare coming in second and third respectively. The top performers will receive bonuses for their hard work. High severity bugs that result in critical security impact earn the most kudos points, and submitting these types of bugs can help researchers get invited to private bounty programs faster. Bugcrowd is looking forward to seeing who will take the top spot in January's Hall of Fame results.
Jan 04, 2017
221 words in the original blog post.
The new year is a great time to reflect on past achievements and set goals for the future. Bugcrowd, a platform that connects bug hunters with bounty programs, has outlined New Year's resolutions for both bug hunters and program managers. For bug hunters, increasing their odds of finding bugs by being prepared, maximizing bounty payouts through effective reporting and learning from others, and staying up-to-date with the community are key. Program owners can improve their success by getting to know their researchers, understanding key performance indicators, and leveling up their programs. The resolutions emphasize the importance of collaboration and mutual respect within the InfoSec community. By working together, individuals can build a more successful and empowering security community.
Jan 03, 2017
812 words in the original blog post.