Home / Companies / Bugcrowd / Blog / March 2017

March 2017 Summaries

18 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
This week I spoke with three security gurus – Dave Farrow, Senior Director Information Security, Barracuda, Alvaro Hoyos, Chief Information Security Officer at OneLogin, and Gene Meltser, Security Architect, Sophos – about their current application security challenges and how they overcome them. Together they explored the common challenges of cybersecurity resource constraints, managing complex technologies and highly sensitive data, and difficulty in coverage at scale. The speakers discussed various strategies to overcome these challenges, including training employees to promote better security processes, building security into the software development lifecycle, using bug bounties as a force multiplier, ensuring fast and consistent feedback, and engaging the security community at scale. These strategies aim to improve security processes, increase efficiency, and reduce the risk of breaches.
Mar 31, 2017 599 words in the original blog post.
Bugcrowd works closely with security teams to run a successful and mutually beneficial bug bounty program by breaking it down into three main stages: planning and strategy, launching and running the program, and learning from and iterating upon it. The process is continuous and involves recommendations and heavy lifting, as Bugcrowd takes care of much of the work involved in setting up a bug bounty program. A deep dive into each stage will be explored, including how to integrate a bug bounty into the security development lifecycle.
Mar 28, 2017 127 words in the original blog post.
In 2010, Barracuda Networks launched a formal bug bounty program, paving the way for other organizations to follow suit. The company has since transitioned to a fully managed Bugcrowd bounty program in 2014, leveraging Crowdcontrol to efficiently handle vulnerability submissions and allocate internal resources. Through their bounty program, Barracuda has seen significant traction over several years, and is now looking to explore new initiatives. This experience has been highly valuable for the company, allowing them to evolve their program and improve overall product security.
Mar 23, 2017 198 words in the original blog post.
Google has raised its top reward for remote code execution bugs in its Google, Blogger, and YouTube domains by 50% to demonstrate appreciation for researchers' significant time dedication to the program. This move highlights the complexities involved in determining when to adjust bounty payout ranges, with managed bug bounty programs becoming the new norm due to the challenges of setting up and maintaining a successful program. Organizations that utilize trusted partners can ensure they get the most out of their bug bounty programs, starting on the right foot by defining scope and pricing targets that are critical to success. The value of bugs is subjective and varies depending on the organization's goals, targets, and security team size, requiring organizations to evaluate business impact and market trends to correctly define bug worth. A "crawl, walk, run" strategy is recommended for increasing rewards as they make sense to the security organization, staying competitive by offering a wide scope with interesting targets, coordinated disclosure programs, and marketing efforts to demonstrate security posture. Ultimately, attracting top researchers requires fair and competitive payment.
Mar 22, 2017 963 words in the original blog post.
Bugcrowd has released a report on the growing trend of security vendors launching bug bounty programs, which have tripled in number over the past two years and now represent the fifth largest industry on their platform. These companies are turning to bug bounties as they face challenges in building internal testing teams due to high demand for skilled cybersecurity resources. The bug bounty model provides value by leveraging the collective expertise of the bug bounty community, with companies like OneLogin, Sophos, and Barracuda reporting immense benefits from working with this community.
Mar 21, 2017 209 words in the original blog post.
We are pleased to announce our February winner, ainulmaker, who submitted a valid bug against thick client applications and will receive a $500 bonus. Our crowd has shown fantastic engagement in submitting bugs this quarter, with a 200% increase in valid submissions compared to previous months. To participate in the promotion, review our list of programs, including Avira, LastPass, Sophos, and more, and test against them to find any bugs or issues. The promotional draws will take place at the end of each month, and all eligible submissions will be entered into these draws. We have put together a collection of resources for those new to thick client software hacking or looking to improve their skills, including books and online challenges. Our team is excited to see what comes through in the next couple of weeks!
Mar 20, 2017 262 words in the original blog post.
The Department of Commerce's "Green Paper" aims to foster the advancement of the Internet of Things by addressing key issues and challenges in its deployment. The document highlights potential benefits and challenges, as well as the role the US Government should play in this evolving landscape. To support this initiative, a coalition of companies including Rapid7, Duo Security, and others has submitted comments recommending that IoT device and software providers adopt coordinated vulnerability disclosure and handling processes for their products. These recommendations aim to improve overall security while protecting security researchers and promoting voluntary adoption of such processes.
Mar 17, 2017 353 words in the original blog post.
The Fitbit Security Team has been awarded two Buggy Awards from Budgrowd, recognizing their "Best Response Time" and "Program of the Year". The team started its bug bounty program about 18 months ago and aimed to treat the security community with respect and gratitude. They achieved this by setting up processes that ensured timely response times and clear communication, which was key to receiving the "Best Response Time" award. The team also received the "Program of the Year" award for balancing resource investment, modifying scope over time, and adding value to their security efforts. By including crowdsourced security in their comprehensive program, Fitbit has experienced fruitful results and is now looking forward to continuing to work with the security community and serving as a model for other teams.
Mar 16, 2017 493 words in the original blog post.
The Bugcrowd team recently held its 2nd Annual Buggy Awards, recognizing top bug hunters and companies running successful bounty programs for their contributions to the crowdsourced security testing community. The awards aim to encourage trust, communication, and collaboration between bug hunters and organizations, setting standards for successful bug bounty programs. By honoring outstanding work, Bugcrowd hopes to make the conversations around vulnerabilities safer and more secure for the internet as a whole. The recognized organizations are building trust within their relationships, strengthening the community, and inspiring others to adopt similar security practices. The awards also aim to encourage more researchers to contribute their insights and perspectives, promoting a vibrant and collaborative bug bounty space.
Mar 16, 2017 740 words in the original blog post.
Nullcon is an annual security conference held in Goa, India that provides a platform for exchanging information on the latest attack vectors and zero day vulnerabilities. The five-day event includes trainings, talks, CTFs and hacking challenges, as well as opportunities to connect with researchers from the Indian infosec community. Bugcrowd was a goodie bag sponsor at the conference, allowing them to engage with their research community and gather feedback on their products and services. A team member presented on how to become a successful bug hunter during the BountyCraft track, while another team member gave an overview of satellite hacking in a talk titled "Explorer's Guide to Shooting Satellite Transponders". The event provided a warm welcome for Bugcrowd and its attendees, with a focus on understanding the needs of their research community.
Mar 15, 2017 496 words in the original blog post.
This month, the "Big Bugs" podcast is taking a break from its usual format to discuss Capture the Flag (CTF) competitions. The podcast features Kevin Chung, who wrote the open-source CTF framework CTFd, and explores the world of CTFs in general, including their history, types, and applications. CTFs are puzzle-based information security challenges that have become a microculture over the past decade, with three common types: Jeopardy-style, Attack-Defense, and mixed. The podcast also delves into the motivations behind participating in CTFs, discusses interesting ways to apply them, and touches on various aspects of information security such as cryptography and reverse engineering. Additionally, it provides a primer for those unfamiliar with CTFs and highlights popular competitions like DEFCON CTF, which qualify winners to participate in the finals. The podcast also explores the role of CTFd, an open-source framework that helps organizations run CTFs, and discusses why CTFs are loved by many, including their ability to teach/learn hacking skills, use as training programs for developers, and bring people together to solve puzzles.
Mar 10, 2017 746 words in the original blog post.
1Password has increased its "capture the flag" challenge reward from $25,000 to $100,000 as part of its security program, demonstrating a serious commitment to customer security and leveraging the power of the crowd to improve its platform. The company recognizes the value of providing fair rewards to researchers who contribute to its security efforts, aligning with Bugcrowd's guidelines on what a bug is worth. This high-reward challenge reflects 1Password's emphasis on using human ingenuity to continually improve its security posture in light of recent security incidents such as Cloudbleed.
Mar 09, 2017 340 words in the original blog post.
The 2nd Annual Buggy Awards have announced finalists for several categories including Honored Program, Researchers' Choice, Honored Bug Hunter, and Outstanding Community Contribution. The award recognizes organizations that demonstrate transparency, commitment, and generosity in their bounty programs as well as top researchers who contribute to the overall Bugcrowd community. Some of the notable finalists include Fitbit, Indeed, Heroku, Spotify, Tesla, Evren, Blum, Mert, and Zseano. The winners will be announced next week, with email notifications available for those interested in staying updated on the ceremony.
Mar 08, 2017 349 words in the original blog post.
The Vulnerability Rating Taxonomy (VRT) has been updated to version 1.0, incorporating feedback from the bug bounty community and expanding its scope to include IoT and automotive applications. The update introduces new top-level categories that are technology-agnostic, allowing for more flexibility in vulnerability prioritization. The changes also bring improvements to existing categories such as Server and Client-Side Injection, with distinct priorities assigned to some vulnerabilities based on context. The VRT is a living document that will continue to evolve over time.
Mar 07, 2017 243 words in the original blog post.
Bugcrowd has announced its February 2017 Hall of Fame winners, recognizing top performers mongo, ansariosama, and zseano for their exceptional work in identifying high-severity bugs. The top three researchers will receive bonuses of $2,500, $1,500, and $1,000 respectively for their outstanding contributions to the platform. To excel on Bugcrowd, researchers must identify high-severity bugs that result in critical security impacts, as these submissions earn the most points and can lead to faster invitations to private bounty programs.
Mar 06, 2017 218 words in the original blog post.
The Bugcrowd platform has been enhanced with the integration of Vulnerability Rating Taxonomy (VRT) and Target Management features into its submission process, allowing researchers to select a customer-specified target and identify vulnerabilities based on VRT classification. This integration reduces effort for all parties, speeds up prioritization and management of vulnerabilities, and improves alignment of expectations for priority or payout of rewardable submissions. The new feature also provides a more granular classification of vulnerabilities, enabling clearer communication with researchers and Security Engineering Team, and delivers improved transparency in vulnerability reporting and filtering capabilities.
Mar 03, 2017 407 words in the original blog post.
The Buggy Awards recognize individuals and organizations that have made significant contributions to the bug bounty space, highlighting achievements in top public bounty programs, researchers' choice, and outstanding community contributions. The awards celebrate transparency, commitment, and excellence in the field, with categories including Best Response Time, Program of the Year, Top Bug Hunter Awards, Most Non-Duplicate P1's, Most Valuable Hacker, and Outstanding Community Contribution.
Mar 01, 2017 488 words in the original blog post.
The 2017 CISO Investment Blueprint was launched to analyze the current state of application security based on survey responses from 100 security decision makers. The blueprint also features interviews with innovators in the industry, including Josh Sokol, an OWASP Board of Directors member and co-founder of Bugcrowd. In these interviews, Sokol discusses his background in computer science and how he became involved in OWASP. He highlights the growth of his open-source side-project, SimpleRisk, which aims to make basic risk management obtainable for organizations of all sizes. Sokol emphasizes the importance of increasing engagement between security professionals and universities to develop secure coding skills in students. He also discusses the role of bug bounties in improving application security, particularly as companies continue to evolve their applications rapidly through agile development. The interviews provide insights into the challenges and opportunities facing security decision-makers in 2017, including the need for more effective communication between developers and security professionals.
Mar 01, 2017 1,286 words in the original blog post.